CVE-2025-5917

Source
https://cve.org/CVERecord?id=CVE-2025-5917
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-5917.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-5917
Downstream
Related
Published
2025-06-09T19:49:13.204Z
Modified
2026-05-15T11:54:33.335314119Z
Severity
  • 2.8 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Libarchive: off by one error in build_ustar_entry_name() at archive_write_set_format_pax.c
Details

A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0.

Database specific
{
    "cwe_ids": [
        "CWE-787"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/5xxx/CVE-2025-5917.json",
    "cna_assigner": "redhat"
}
References

Affected packages