Logo
vulnerabilityCVE-2025-5914
Name
CVE-2025-5914
Source
NVD ( link)Debian ( link)
Description
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
libarchive
Patched

Vulnerability Ratings#


7.8
CVSSv31
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.8.7
Not Affected
buildroot
master
3.8.8
Not Affected
openwrt
master
3.8.1-r2
Not Affected
openwrt
openwrt-25.12
3.8.1-r2
Not Affected
yocto
master
3.8.7
Not Affected
yocto
scarthgap
3.7.9
Patched

Resolved with patches#


libarchive (yocto:kirkstone)

#
Title
Author
Resolve
1
rar: Fix double free with over 4 billion nodes (#2598)
Tobias Stoeckmann <stoeckmann@users.noreply.github.com>
CVE-2025-5914

libarchive (yocto:scarthgap)

#
Title
Author
Resolve
1
rar: Fix double free with over 4 billion nodes (#2598)
Tobias Stoeckmann <stoeckmann@users.noreply.github.com>
CVE-2025-5914