CVE-2025-5914 - CVE House
Back to Database
Status published High CVE-2025-5914

Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c

Vulnerability Description

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-5914

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat OpenShift Container Platform 4.14, Red Hat OpenShift Container Platform 4.15, Red Hat OpenShift Container Platform 4.16, Red Hat OpenShift Container Platform 4.17, Red Hat OpenShift Container Platform 4.18, Red Hat OpenShift Container Platform 4.19, Red Hat OpenShift Container Platform 4.20, Red Hat Web Terminal 1.11 on RHEL 9, Red Hat Web Terminal 1.12 on RHEL 9, RHOSS-1.36-RHEL-8, cert-manager operator for Red Hat OpenShift 1.16, OpenShift Compliance Operator 1, OpenShift File Integrity Operator - FIO 1, Red Hat Discovery 2, Red Hat Insights proxy 1.5, Red Hat OpenShift distributed tracing 3.5.1, Red Hat OpenShift sandboxed containers 1.1, Red Hat Enterprise Linux 6
Vulnerable Versions:
0, 0:3.7.7-4.el10_0, 0:3.1.2-14.el7_9.1, 0:3.3.3-6.el8_10, 0:3.3.2-8.el8_2.1, 0:3.3.3-1.el8_4.1, 0:3.3.3-6.el8_6, 0:3.3.3-5.el8_8.1, 0:3.5.3-6.el9_6, 0:3.5.3-2.el9_0.1, 0:3.5.3-5.el9_2, 0:3.5.3-4.el9_4.1, 414.92.202510211419-0, 415.92.202601271320-0, 416.94.202601071926-0, 417.94.202510112152-0, 418.94.202510230424-0, 4.19.9.6.202510140714-0, 4.20.9.6.202509251656-0, 1.11-19, 1.11-8, 1.12-4, 1.36.0-11, 1.36.0-10, 1.36.0-4, 1.36.0-9, 1.36.0-12, 1.36.0-18, 1.36.0-7, v1.16.5-1760515757, 1.8.0, v1.3, 2.2.1-1758555934, 1.5.6-1756187445, rhosdt-3.5-1756116455, rhosdt-3.5-1756116482, rhosdt-3.5-1756116441, rhosdt-3.5-1756116449, rhosdt-3.5-1756116439, rhosdt-3.5-1756116447, rhosdt-3.5-1756128595, rhosdt-3.5-1756125872, rhosdt-3.5-1756116445, 1.10.2-1757422110, 1.10.2-1757421846, 1.10.2-1757421804, 1.10.2-1757422070, 1.10.2-1757421879, 1.10.2-1757422401, 1.10.2-1757421890

Timeline

Official Publish: June 9th, 2025
Last Modified: July 14th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)