Logo
vulnerabilityCVE-2025-5918
Name
CVE-2025-5918
Source
NVD ( link)Debian ( link)
Description
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libarchive
Patched

Vulnerability Ratings#


3.9
CVSSv31
6.6
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.8.7
Not Affected
buildroot
master
3.8.8
Not Affected
openwrt
master
3.8.1-r2
Not Affected
openwrt
openwrt-25.12
3.8.1-r2
Not Affected
yocto
kirkstone
3.6.2
Patched
yocto
master
3.8.7
Not Affected

Resolved with patches#


libarchive (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix FILE_skip regression
Tobias Stoeckmann <tobias@stoeckmann.org>
CVE-2025-5918
2
Do not skip past EOF while reading (#2584)
Tobias Stoeckmann <stoeckmann@users.noreply.github.com>
CVE-2025-5918

libarchive (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix FILE_skip regression
Tobias Stoeckmann <tobias@stoeckmann.org>
CVE-2025-5918
2
Do not skip past EOF while reading (#2584)
Tobias Stoeckmann <stoeckmann@users.noreply.github.com>
CVE-2025-5918
3
Improve lseek handling (#2564)
Tobias Stoeckmann <stoeckmann@users.noreply.github.com>
CVE-2025-5918