A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZ…
中危 CVSS 6.6
摘要
A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
- :
数据来源
- NVD DATABASE
原始链接
- https://access.redhat.com/security/cve/CVE-2025-5915 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2370865 Issue Tracking
- https://github.com/libarchive/libarchive/pull/2599 Patch
- https://github.com/libarchive/libarchive/releases/tag/v3.8.0 Release Notes
时间线
- nvd_ingest NVD