CVE-2025-5918: Out-of-bounds Read
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
AI Analysis
Technical Summary
This vulnerability in libarchive affects Red Hat Enterprise Linux 10 and involves an out-of-bounds read triggered by piping file streams into bsdtar. The flaw can cause the program to read beyond the intended file boundary, leading to possible memory corruption or denial-of-service. The CVSS 3.1 vector indicates local attack vector, low complexity, requiring privileges and user interaction, with limited confidentiality impact and no integrity impact. The Red Hat advisory is published but does not provide explicit patch or fix details in the provided content.
Potential Impact
Successful exploitation may lead to unpredictable program behavior, memory corruption, or denial-of-service conditions. Confidentiality impact is low, with no integrity impact. The attack requires local access and user interaction, limiting the scope of exploitation. No known active exploits have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2025-5918 for current remediation guidance. Until a fix is confirmed, avoid piping untrusted file streams into bsdtar or restrict local user access to vulnerable components. Monitor vendor updates for official patches or workarounds.
CVE-2025-5918: Out-of-bounds Read
Description
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
CVSS v3.1
Score 3.9low
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in libarchive affects Red Hat Enterprise Linux 10 and involves an out-of-bounds read triggered by piping file streams into bsdtar. The flaw can cause the program to read beyond the intended file boundary, leading to possible memory corruption or denial-of-service. The CVSS 3.1 vector indicates local attack vector, low complexity, requiring privileges and user interaction, with limited confidentiality impact and no integrity impact. The Red Hat advisory is published but does not provide explicit patch or fix details in the provided content.
Potential Impact
Successful exploitation may lead to unpredictable program behavior, memory corruption, or denial-of-service conditions. Confidentiality impact is low, with no integrity impact. The attack requires local access and user interaction, limiting the scope of exploitation. No known active exploits have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2025-5918 for current remediation guidance. Until a fix is confirmed, avoid piping untrusted file streams into bsdtar or restrict local user access to vulnerable components. Monitor vendor updates for official patches or workarounds.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- redhat
- Date Reserved
- 2025-06-09T08:11:22.154Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2025-5918","vendor":"Red Hat"}]
Threat ID: 68487f561b0bd07c3938a58d
Added to database: 06/10/2025, 18:54:14 UTC
Last enriched: 07/02/2026, 21:58:16 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 139
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.