CVE-2025-5914

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.
References
Link Resource
https://access.redhat.com/errata/RHSA-2025:14130 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:14135 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:14137 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:14141 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:14142 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:14525 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:14528 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:14594 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:14644 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:14808 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:14810 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:14828 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:15024 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:15397 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:15709 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:15827 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:15828 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:16524 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:18217 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:18218 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:18219 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:19041 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:19046 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:21885 Third Party Advisory
https://access.redhat.com/errata/RHSA-2025:21913 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:0326 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:0934
https://access.redhat.com/errata/RHSA-2026:1541
https://access.redhat.com/security/cve/CVE-2025-5914 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2370861 Issue Tracking Third Party Advisory
https://github.com/libarchive/libarchive/pull/2598 Exploit Issue Tracking Patch
https://github.com/libarchive/libarchive/releases/tag/v3.8.0 Release Notes
https://github.com/libarchive/libarchive/pull/2598 Exploit Issue Tracking Patch
Configurations

Configuration 1 (hide)

cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

05 Feb 2026, 20:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:1541 -

05 Feb 2026, 18:16

Type Values Removed Values Added
CWE CWE-415 CWE-190

22 Jan 2026, 05:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:0934 -

21 Jan 2026, 15:16

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2025:14130 - () https://access.redhat.com/errata/RHSA-2025:14130 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:14135 - () https://access.redhat.com/errata/RHSA-2025:14135 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:14137 - () https://access.redhat.com/errata/RHSA-2025:14137 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:14141 - () https://access.redhat.com/errata/RHSA-2025:14141 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:14142 - () https://access.redhat.com/errata/RHSA-2025:14142 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:14525 - () https://access.redhat.com/errata/RHSA-2025:14525 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:14528 - () https://access.redhat.com/errata/RHSA-2025:14528 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:14594 - () https://access.redhat.com/errata/RHSA-2025:14594 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:14644 - () https://access.redhat.com/errata/RHSA-2025:14644 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:14808 - () https://access.redhat.com/errata/RHSA-2025:14808 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:14810 - () https://access.redhat.com/errata/RHSA-2025:14810 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:14828 - () https://access.redhat.com/errata/RHSA-2025:14828 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:15024 - () https://access.redhat.com/errata/RHSA-2025:15024 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:15397 - () https://access.redhat.com/errata/RHSA-2025:15397 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:15709 - () https://access.redhat.com/errata/RHSA-2025:15709 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:15827 - () https://access.redhat.com/errata/RHSA-2025:15827 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:15828 - () https://access.redhat.com/errata/RHSA-2025:15828 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:16524 - () https://access.redhat.com/errata/RHSA-2025:16524 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:18217 - () https://access.redhat.com/errata/RHSA-2025:18217 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:18218 - () https://access.redhat.com/errata/RHSA-2025:18218 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:18219 - () https://access.redhat.com/errata/RHSA-2025:18219 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:19041 - () https://access.redhat.com/errata/RHSA-2025:19041 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:19046 - () https://access.redhat.com/errata/RHSA-2025:19046 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:21885 - () https://access.redhat.com/errata/RHSA-2025:21885 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2025:21913 - () https://access.redhat.com/errata/RHSA-2025:21913 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2026:0326 - () https://access.redhat.com/errata/RHSA-2026:0326 - Third Party Advisory

15 Jan 2026, 19:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:0326 -

07 Jan 2026, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.3
v2 : unknown
v3 : 7.8

22 Nov 2025, 03:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:21913 -

20 Nov 2025, 21:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:21885 -

30 Oct 2025, 06:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:19041 -

29 Oct 2025, 13:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:19046 -

22 Oct 2025, 07:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:18217 -

22 Oct 2025, 06:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:18218 -

21 Oct 2025, 20:20

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:15397 -

16 Oct 2025, 09:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:18219 -

23 Sep 2025, 20:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:16524 -

15 Sep 2025, 18:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:15827 -

15 Sep 2025, 16:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:15828 -

11 Sep 2025, 16:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:15709 -

02 Sep 2025, 03:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:15024 -

28 Aug 2025, 09:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:14808 -
  • () https://access.redhat.com/errata/RHSA-2025:14810 -

28 Aug 2025, 07:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:14828 -

27 Aug 2025, 16:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:14644 -

26 Aug 2025, 10:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:14594 -

25 Aug 2025, 21:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:14525 -
  • () https://access.redhat.com/errata/RHSA-2025:14528 -

20 Aug 2025, 15:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:14142 -

20 Aug 2025, 10:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:14141 -

20 Aug 2025, 09:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:14130 -
  • () https://access.redhat.com/errata/RHSA-2025:14135 -
  • () https://access.redhat.com/errata/RHSA-2025:14137 -

12 Aug 2025, 11:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 3.9
v2 : unknown
v3 : 7.3

20 Jun 2025, 14:49

Type Values Removed Values Added
First Time Redhat enterprise Linux
Libarchive
Redhat openshift Container Platform
Libarchive libarchive
Redhat
CPE cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
References () https://access.redhat.com/security/cve/CVE-2025-5914 - () https://access.redhat.com/security/cve/CVE-2025-5914 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2370861 - () https://bugzilla.redhat.com/show_bug.cgi?id=2370861 - Issue Tracking, Third Party Advisory
References () https://github.com/libarchive/libarchive/pull/2598 - () https://github.com/libarchive/libarchive/pull/2598 - Exploit, Issue Tracking, Patch
References () https://github.com/libarchive/libarchive/releases/tag/v3.8.0 - () https://github.com/libarchive/libarchive/releases/tag/v3.8.0 - Release Notes

10 Jun 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en la librería libarchive, específicamente en la función archive_read_format_rar_seek_data(). Esta falla implica un desbordamiento de enteros que puede provocar una condición de doble liberación. Explotar una vulnerabilidad de doble liberación puede provocar corrupción de memoria, lo que permite a un atacante ejecutar código arbitrario o causar una denegación de servicio.
References () https://github.com/libarchive/libarchive/pull/2598 - () https://github.com/libarchive/libarchive/pull/2598 -

09 Jun 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-09 20:15

Updated : 2026-02-05 20:15


NVD link : CVE-2025-5914

Mitre link : CVE-2025-5914

CVE.ORG link : CVE-2025-5914


JSON object : View

Products Affected

libarchive

  • libarchive

redhat

  • openshift_container_platform
  • enterprise_linux
CWE
CWE-190

Integer Overflow or Wraparound