CVE-2025-5914

Source
https://cve.org/CVERecord?id=CVE-2025-5914
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-5914.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-5914
Downstream
Related
Published
2025-06-09T19:53:48.923Z
Modified
2026-05-15T11:54:09.034494016Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c
Details

A vulnerability has been identified in the libarchive library, specifically within the archivereadformatrarseek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.

Database specific
{
    "cna_assigner": "redhat",
    "cwe_ids": [
        "CWE-190"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/5xxx/CVE-2025-5914.json"
}
References

Affected packages