Logo
vulnerabilityCVE-2025-5916
Name
CVE-2025-5916
Source
NVD ( link)Debian ( link)
Description
A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libarchive
Patched

Vulnerability Ratings#


3.9
CVSSv31
5.6
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.8.7
Not Affected
buildroot
master
3.8.8
Not Affected
openwrt
master
3.8.1-r2
Not Affected
openwrt
openwrt-25.12
3.8.1-r2
Not Affected
yocto
master
3.8.7
Not Affected
yocto
scarthgap
3.7.9
Patched

Resolved with patches#


libarchive (yocto:kirkstone)

#
Title
Author
Resolve
1
warc: Prevent signed integer overflow (#2568)
Tobias Stoeckmann <stoeckmann@users.noreply.github.com>
CVE-2025-5916

libarchive (yocto:scarthgap)

#
Title
Author
Resolve
1
warc: Prevent signed integer overflow (#2568)
Tobias Stoeckmann <stoeckmann@users.noreply.github.com>
CVE-2025-5916