Vulnerability Description
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libarchive | Libarchive | < 3.8.0 |
| Redhat | Openshift Container Platform | 4.0 |
| Redhat | Enterprise Linux | 6.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2025:14130Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14135Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14137Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14141Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14142Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14525Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14528Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14594Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14644Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14808Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14810Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:14828Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:15024Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:15397Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:15709Third Party Advisory
FAQ
What is CVE-2025-5914?
CVE-2025-5914 is a vulnerability with a CVSS score of 7.8 (HIGH). A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to ...
How severe is CVE-2025-5914?
CVE-2025-5914 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-5914?
Check the references section above for vendor advisories and patch information. Affected products include: Libarchive Libarchive, Redhat Openshift Container Platform, Redhat Enterprise Linux.