File Handling Vulnerability in Libarchive Library by Red Hat
CVE-2025-5917

2.8LOW

What is CVE-2025-5917?

A vulnerability exists in the libarchive library, stemming from an off-by-one miscalculation related to file name handling. This flaw can cause a 1-byte write overflow, which might lead to adjacent memory corruption. Such corruption can result in unpredictable behavior of affected applications, including software crashes or potentially serve as a foundational element for more advanced exploit techniques. It is crucial for users to be aware of the risks associated with this vulnerability and to apply any relevant patches or updates promptly.

References

CVSS V3.1

Score:
2.8
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-5917 : File Handling Vulnerability in Libarchive Library by Red Hat