is an open-source BSD-licensed C programming library that provides streaming access to a variety of different archive formats, including tar, cpio, pax, zip, and ISO9660 images. The distribution also includes bsdtar and bsdcpio, full-featured implementations of tar and cpio that use .
Security Fix(es):
An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).(CVE-2025-60753)
{
"severity": "Medium"
}{
"src": [
"libarchive-3.7.1-8.oe2403.src.rpm"
],
"aarch64": [
"bsdcat-3.7.1-8.oe2403.aarch64.rpm",
"bsdcpio-3.7.1-8.oe2403.aarch64.rpm",
"bsdtar-3.7.1-8.oe2403.aarch64.rpm",
"bsdunzip-3.7.1-8.oe2403.aarch64.rpm",
"libarchive-3.7.1-8.oe2403.aarch64.rpm",
"libarchive-debuginfo-3.7.1-8.oe2403.aarch64.rpm",
"libarchive-debugsource-3.7.1-8.oe2403.aarch64.rpm",
"libarchive-devel-3.7.1-8.oe2403.aarch64.rpm"
],
"noarch": [
"libarchive-help-3.7.1-8.oe2403.noarch.rpm"
],
"x86_64": [
"bsdcat-3.7.1-8.oe2403.x86_64.rpm",
"bsdcpio-3.7.1-8.oe2403.x86_64.rpm",
"bsdtar-3.7.1-8.oe2403.x86_64.rpm",
"bsdunzip-3.7.1-8.oe2403.x86_64.rpm",
"libarchive-3.7.1-8.oe2403.x86_64.rpm",
"libarchive-debuginfo-3.7.1-8.oe2403.x86_64.rpm",
"libarchive-debugsource-3.7.1-8.oe2403.x86_64.rpm",
"libarchive-devel-3.7.1-8.oe2403.x86_64.rpm"
]
}