CVE-2025-5914
Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.
Se ha identificado una vulnerabilidad en la librería libarchive, específicamente en la función archive_read_format_rar_seek_data(). Esta falla implica un desbordamiento de enteros que puede provocar una condición de doble liberación. Explotar una vulnerabilidad de doble liberación puede provocar corrupción de memoria, lo que permite a un atacante ejecutar código arbitrario o causar una denegación de servicio.
It was discovered that libarchive incorrectly handled certain RAR archive files. An attacker could possibly use this issue to execute arbitrary code or cause a denial of service. It was discovered that libarchive incorrectly handled certain RAR archive files. An attacker could possibly use this issue to read sensitive data or cause a denial of service. It was discovered that libarchive incorrectly handled certain WARC archive files. If a user or automated system were tricked into processing a specially crafted WARC archive, an attacker could use this issue to cause libarchive to crash, resulting in a denial of service.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-06-09 CVE Reserved
- 2025-06-09 CVE Published
- 2026-01-26 First Exploit
- 2026-04-05 EPSS Updated
- 2026-04-20 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-190: Integer Overflow or Wraparound
- CWE-415: Double Free
CAPEC
References (34)
| URL | Tag | Source |
|---|---|---|
| https://github.com/libarchive/libarchive/pull/2598 | ||
| https://github.com/libarchive/libarchive/releases/tag/v3.8.0 |
| URL | Date | SRC |
|---|---|---|
| https://packetstorm.news/files/id/214358 | 2026-01-26 | |
| https://packetstorm.news/files/id/214604 | 2026-01-30 |
| URL | Date | SRC |
|---|
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Centos Search vendor "Centos" | Centos Search vendor "Centos" for product "Centos" | * | - |
Affected
| ||||||
| Libarchive Search vendor "Libarchive" | Libarchive Search vendor "Libarchive" for product "Libarchive" | * | - |
Affected
| ||||||
| Oracle Search vendor "Oracle" | Linux Search vendor "Oracle" for product "Linux" | * | - |
Affected
| ||||||
| Red Hat Search vendor "Red Hat" | Enterprise Linux Search vendor "Red Hat" for product "Enterprise Linux" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Cert-manager Operator For Red Hat Openshift Search vendor "Redhat" for product "Cert-manager Operator For Red Hat Openshift" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Cert Manager Search vendor "Redhat" for product "Cert Manager" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Confidential Compute Attestation Search vendor "Redhat" for product "Confidential Compute Attestation" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Discovery Search vendor "Redhat" for product "Discovery" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Insights Proxy Search vendor "Redhat" for product "Insights Proxy" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Openshift Search vendor "Redhat" for product "Openshift" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Openshift Compliance Operator Search vendor "Redhat" for product "Openshift Compliance Operator" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Openshift Container Platform Search vendor "Redhat" for product "Openshift Container Platform" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Openshift Distributed Tracing Search vendor "Redhat" for product "Openshift Distributed Tracing" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Openshift File Integrity Operator Search vendor "Redhat" for product "Openshift File Integrity Operator" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Rhel E4s Search vendor "Redhat" for product "Rhel E4s" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Rhel Eus Search vendor "Redhat" for product "Rhel Eus" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Web Terminal Search vendor "Redhat" for product "Web Terminal" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Webterminal Search vendor "Redhat" for product "Webterminal" | * | - |
Affected
| ||||||
| Alibabacloud Search vendor "Alibabacloud" | Alibaba Cloud Linux 3 Search vendor "Alibabacloud" for product "Alibaba Cloud Linux 3" | * | - |
Affected
| ||||||
| Alma Search vendor "Alma" | Linux Search vendor "Alma" for product "Linux" | * | - |
Affected
| ||||||
| Amazon Search vendor "Amazon" | Linux Search vendor "Amazon" for product "Linux" | * | - |
Affected
| ||||||
| Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | * | - |
Affected
| ||||||
| Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | * | - |
Affected
| ||||||
| Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | * | - |
Affected
| ||||||
| Freebsd Search vendor "Freebsd" | Freebsd Search vendor "Freebsd" for product "Freebsd" | * | - |
Affected
| ||||||
| Huawei Search vendor "Huawei" | Euleros Search vendor "Huawei" for product "Euleros" | * | - |
Affected
| ||||||
| Nutanix Search vendor "Nutanix" | Ahv Search vendor "Nutanix" for product "Ahv" | * | - |
Affected
| ||||||
| Nutanix Search vendor "Nutanix" | Aos Search vendor "Nutanix" for product "Aos" | * | - |
Affected
| ||||||
| Opensuse Search vendor "Opensuse" | Leap Search vendor "Opensuse" for product "Leap" | * | - |
Affected
| ||||||
| Oracle Search vendor "Oracle" | Linux Search vendor "Oracle" for product "Linux" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Openshift Search vendor "Redhat" for product "Openshift" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Rhel Aus Search vendor "Redhat" for product "Rhel Aus" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Rhel E4s Search vendor "Redhat" for product "Rhel E4s" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Rhel Els Search vendor "Redhat" for product "Rhel Els" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Rhel Eus Search vendor "Redhat" for product "Rhel Eus" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Rhel Eus Long Life Search vendor "Redhat" for product "Rhel Eus Long Life" | * | - |
Affected
| ||||||
| Redhat Search vendor "Redhat" | Rhel Tus Search vendor "Redhat" for product "Rhel Tus" | * | - |
Affected
| ||||||
| Rocky Search vendor "Rocky" | Linux Search vendor "Rocky" for product "Linux" | * | - |
Affected
| ||||||
| Suse Search vendor "Suse" | Sle-module-basesystem Search vendor "Suse" for product "Sle-module-basesystem" | * | - |
Affected
| ||||||
| Suse Search vendor "Suse" | Sle-module-development-tools Search vendor "Suse" for product "Sle-module-development-tools" | * | - |
Affected
| ||||||
| Suse Search vendor "Suse" | Sle Hpc-espos Search vendor "Suse" for product "Sle Hpc-espos" | * | - |
Affected
| ||||||
| Suse Search vendor "Suse" | Sle Hpc-ltss Search vendor "Suse" for product "Sle Hpc-ltss" | * | - |
Affected
| ||||||
| Suse Search vendor "Suse" | Sle Hpc Search vendor "Suse" for product "Sle Hpc" | * | - |
Affected
| ||||||
| Suse Search vendor "Suse" | Sled Search vendor "Suse" for product "Sled" | * | - |
Affected
| ||||||
| Suse Search vendor "Suse" | Sles-ltss-extended-security Search vendor "Suse" for product "Sles-ltss-extended-security" | * | - |
Affected
| ||||||
| Suse Search vendor "Suse" | Sles-ltss Search vendor "Suse" for product "Sles-ltss" | * | - |
Affected
| ||||||
| Suse Search vendor "Suse" | Sles Search vendor "Suse" for product "Sles" | * | - |
Affected
| ||||||
| Suse Search vendor "Suse" | Sles Sap Search vendor "Suse" for product "Sles Sap" | * | - |
Affected
| ||||||
| Suse Search vendor "Suse" | Suse-manager-proxy-lts Search vendor "Suse" for product "Suse-manager-proxy-lts" | * | - |
Affected
| ||||||
| Suse Search vendor "Suse" | Suse-manager-server-lts Search vendor "Suse" for product "Suse-manager-server-lts" | * | - |
Affected
| ||||||
| Tencent Search vendor "Tencent" | Tencentos Server Search vendor "Tencent" for product "Tencentos Server" | * | - |
Affected
| ||||||
| Uos Search vendor "Uos" | Uos Server 20 Search vendor "Uos" for product "Uos Server 20" | * | - |
Affected
| ||||||
