CVE-2025-5918: Libarchive

Medium severity, CVSS 6.6. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.

Affected products

  • Libarchive Libarchive: before 3.8.0 (fixed in 3.8.0)
  • Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 8.0 only; version 9.0 only
  • Red Hat Openshift Container Platform: version 4.0 only

Published 2025-06-09. Last modified 2026-09-01.