Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-63786.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-63786
Upstream
Published
2025-06-09T20:15:26Z
Modified
2026-04-01T05:20:13.045830Z
Summary
CVE-2025-5915 affecting package libarchive for versions less than 3.7.7-3
Details

A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.

References

Affected packages

Azure Linux:3 / libarchive

Package

Name
libarchive
Purl
pkg:rpm/azure-linux/libarchive

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.7.7-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-63786.json"