---
id: CVE-2025-5914
title: >-
  A vulnerability has been identified in the libarchive library, specifically
  within the archive_read_format_rar_seek_data() function
summary: >-
  A vulnerability has been identified in the libarchive library, specifically
  within the archive_read_format_rar_seek_data() function. This flaw involves an
  integer overflow that can ultimately lead to a double-free condition.
  Exploiting a…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-190
vendor: libarchive
product: libarchive
affected:
  - libarchive < 3.8.0
  - openshift_container_platform = 4.0
  - enterprise_linux = 6.0
  - enterprise_linux = 7.0
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
  - enterprise_linux = 10.0
patched:
  - libarchive 3.8.0
published: '2025-06-09'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:17:28.047'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-5914'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:14130'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14135'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14137'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14141'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14142'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14525'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14528'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14594'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14644'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14808'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14810'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14828'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15024'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15397'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15709'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15827'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15828'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:16524'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:18217'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:18218'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:18219'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:19041'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:19046'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:21885'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:21913'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:0326'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:0934'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:1541'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-5914'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2370861'
    label: secalert@redhat.com
  - url: 'https://github.com/libarchive/libarchive/pull/2598'
    label: secalert@redhat.com
  - url: 'https://github.com/libarchive/libarchive/releases/tag/v3.8.0'
    label: secalert@redhat.com
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-585531.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://github.com/libarchive/libarchive/pull/2598'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5914.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-5914'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-5914'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2025-06-10T15:14:35.773233Z'
epss: 0.00439
epssPercentile: 0.35429
ingestedAt: '2026-06-29T13:24:34.355Z'
---

## Overview

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.

## Affected

- `libarchive < 3.8.0`
- `openshift_container_platform = 4.0`
- `enterprise_linux = 6.0`
- `enterprise_linux = 7.0`
- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`
- `enterprise_linux = 10.0`

## Remediation

Upgrade past the affected range:

- `libarchive 3.8.0`

## Vendor advisories

- **RHSA-2025:14828** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS) · released 2025-08-28 · [advisory](https://access.redhat.com/errata/RHSA-2025:14828)
- **RHSA-2026:0934** · Red Hat · fixed in: 8Base-Openshift-Serverless-1.36 · released 2026-01-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:0934)
- **RHSA-2025:19041** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2025-10-30 · [advisory](https://access.redhat.com/errata/RHSA-2025:19041)
- **RHSA-2026:1541** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.15 · released 2026-02-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:1541)
- **RHSA-2026:0326** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-01-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:0326)
- **RHSA-2025:18218** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.17 · released 2025-10-22 · [advisory](https://access.redhat.com/errata/RHSA-2025:18218)
- **RHSA-2025:19046** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2025-10-29 · [advisory](https://access.redhat.com/errata/RHSA-2025:19046)
- **RHSA-2025:18217** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2025-10-22 · [advisory](https://access.redhat.com/errata/RHSA-2025:18217)
- **RHSA-2025:15397** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.20 · released 2025-10-21 · [advisory](https://access.redhat.com/errata/RHSA-2025:15397)
- **RHSA-2025:15828** · Red Hat · fixed in: Red Hat Web Terminal 1.11 on RHEL 9 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15828)
- **RHSA-2025:15827** · Red Hat · fixed in: Red Hat Web Terminal 1.12 on RHEL 9 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15827)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 6 · no fix planned: Red Hat Enterprise Linux 6 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5914.json)
