Memory Allocation Vulnerability in libarchive's bsdtar Product
CVE-2025-60753
5.5MEDIUM
What is CVE-2025-60753?
A vulnerability exists in libarchive's bsdtar that affects versions prior to 3.8.1. The issue arises in the apply_substitution function within the subst.c file, which processes specifically crafted -s substitution rules. Successful exploitation can trigger unbounded memory allocation, leading to a denial of service situation characterized by an Out-of-Memory (OOM) crash. Users are advised to upgrade to the latest version to mitigate the risk.
