CVE-2024-48958: Libarchive

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.

Affected products

  • Libarchive Libarchive: from 3.6.0, before 3.7.5 (fixed in 3.7.5)

Published 2024-10-10. Last modified 2026-06-17.