CVE-2025-5914

HIGH

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.

CVSS v3.1 Score

7.8
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Complexity
LOW
Privileges
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Published: 6/9/2025Modified: 8/3/2026

Related Intelligence (0)

No articles currently reference this CVE.

References (34)

https://access.redhat.com/errata/RHSA-2025:14130Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:14135Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:14137Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:14141Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:14142Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:14525Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:14528Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:14594Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:14644Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:14808Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:14810Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:14828Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:15024Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:15397Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:15709Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:15827Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:15828Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:16524Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:18217Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:18218Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:18219Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:19041Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:19046Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:21885Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2025:21913Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2026:0326Third Party Advisoryhttps://access.redhat.com/errata/RHSA-2026:0934https://access.redhat.com/errata/RHSA-2026:1541https://access.redhat.com/security/cve/CVE-2025-5914Third Party Advisoryhttps://bugzilla.redhat.com/show_bug.cgi?id=2370861Issue TrackingThird Party Advisoryhttps://github.com/libarchive/libarchive/pull/2598ExploitIssue Trackinghttps://github.com/libarchive/libarchive/releases/tag/v3.8.0Release Noteshttps://cert-portal.siemens.com/productcert/html/ssa-585531.htmlhttps://github.com/libarchive/libarchive/pull/2598ExploitIssue Tracking