CVE-2025-60753: Libarchive

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).

Affected products

Published 2025-11-05. Last modified 2026-06-17.