{"id":"CVE-2025-5914","title":"A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function","summary":"A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-190"],"vendor":"libarchive","product":"libarchive","affected":["libarchive < 3.8.0","openshift_container_platform = 4.0","enterprise_linux = 6.0","enterprise_linux = 7.0","enterprise_linux = 8.0","enterprise_linux = 9.0","enterprise_linux = 10.0"],"patched":["libarchive 3.8.0"],"published":"2025-06-09","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:17:28.047","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-5914","references":[{"url":"https://access.redhat.com/errata/RHSA-2025:14130","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14135","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14137","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14141","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14142","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14525","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14528","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14594","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14644","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14808","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14810","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:14828","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:15024","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:15397","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:15709","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:15827","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:15828","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:16524","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:18217","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:18218","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:18219","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:19041","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:19046","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:21885","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:21913","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:0326","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:0934","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:1541","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-5914","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2370861","label":"secalert@redhat.com"},{"url":"https://github.com/libarchive/libarchive/pull/2598","label":"secalert@redhat.com"},{"url":"https://github.com/libarchive/libarchive/releases/tag/v3.8.0","label":"secalert@redhat.com"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-585531.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"},{"url":"https://github.com/libarchive/libarchive/pull/2598","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5914.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-5914"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-5914"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2025-06-10T15:14:35.773233Z"},"epss":0.00439,"epssPercentile":0.37604,"ingestedAt":"2026-06-29T13:24:34.355Z","slug":"CVE-2025-5914","body":"## Overview\n\nA vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.\n\n## Affected\n\n- `libarchive < 3.8.0`\n- `openshift_container_platform = 4.0`\n- `enterprise_linux = 6.0`\n- `enterprise_linux = 7.0`\n- `enterprise_linux = 8.0`\n- `enterprise_linux = 9.0`\n- `enterprise_linux = 10.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `libarchive 3.8.0`\n\n## Vendor advisories\n\n- **RHSA-2025:14828** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS) · released 2025-08-28 · [advisory](https://access.redhat.com/errata/RHSA-2025:14828)\n- **RHSA-2026:0934** · Red Hat · fixed in: 8Base-Openshift-Serverless-1.36 · released 2026-01-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:0934)\n- **RHSA-2025:19041** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2025-10-30 · [advisory](https://access.redhat.com/errata/RHSA-2025:19041)\n- **RHSA-2026:1541** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.15 · released 2026-02-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:1541)\n- **RHSA-2026:0326** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-01-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:0326)\n- **RHSA-2025:18218** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.17 · released 2025-10-22 · [advisory](https://access.redhat.com/errata/RHSA-2025:18218)\n- **RHSA-2025:19046** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2025-10-29 · [advisory](https://access.redhat.com/errata/RHSA-2025:19046)\n- **RHSA-2025:18217** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2025-10-22 · [advisory](https://access.redhat.com/errata/RHSA-2025:18217)\n- **RHSA-2025:15397** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.20 · released 2025-10-21 · [advisory](https://access.redhat.com/errata/RHSA-2025:15397)\n- **RHSA-2025:15828** · Red Hat · fixed in: Red Hat Web Terminal 1.11 on RHEL 9 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15828)\n- **RHSA-2025:15827** · Red Hat · fixed in: Red Hat Web Terminal 1.12 on RHEL 9 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15827)\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 6 · no fix planned: Red Hat Enterprise Linux 6 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5914.json)","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":4845,"id":"CVE-2025-5914","ts":1788887211467,"field":"exploit_available","old":"false","new":"true"},{"seq":3728,"id":"CVE-2025-5914","ts":1788886327569,"field":"exploit_available","old":"true","new":"false"},{"seq":2573,"id":"CVE-2025-5914","ts":1788883008880,"field":"exploit_available","old":"false","new":"true"},{"seq":1602,"id":"CVE-2025-5914","ts":1788882409022,"field":"exploit_available","old":"true","new":"false"},{"seq":230,"id":"CVE-2025-5914","ts":1788881642371,"field":"exploit_available","old":"false","new":"true"}]}