Logo
vulnerabilityCVE-2025-5917
Name
CVE-2025-5917
Source
NVD ( link)Debian ( link)
Description
A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libarchive
Patched

Vulnerability Ratings#


2.8
CVSSv31
5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.8.7
Not Affected
buildroot
master
3.8.8
Not Affected
openwrt
master
3.8.1-r2
Not Affected
openwrt
openwrt-25.12
3.8.1-r2
Not Affected
yocto
master
3.8.7
Not Affected
yocto
scarthgap
3.7.9
Patched

Resolved with patches#


libarchive (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix overflow in build_ustar_entry (#2588)
Brian Campbell <Brian.Campbell@ed.ac.uk>
CVE-2025-5917

libarchive (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix overflow in build_ustar_entry (#2588)
Brian Campbell <Brian.Campbell@ed.ac.uk>
CVE-2025-5917