CVE-2025-5916

LOW

libarchive < 3.8.0 - Integer Overflow via Malicious WARC Archive

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.

References (4)

Core 4

Scores

CVSS v3 3.9
EPSS 0.0010
EPSS Percentile 27.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-190
Status published
Products (7)
libarchive/libarchive < 3.8.0
redhat/enterprise_linux 6.0
redhat/enterprise_linux 7.0
redhat/enterprise_linux 8.0
redhat/enterprise_linux 9.0
redhat/enterprise_linux 10.0
redhat/openshift_container_platform 4.0
Published Jun 09, 2025
Tracked Since Feb 18, 2026