CVE-2025-5915
Publication date 9 June 2025
Last updated 6 April 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libarchive | 25.10 questing |
Fixed 3.7.7-0ubuntu3
|
| 24.04 LTS noble |
Fixed 3.7.2-2ubuntu0.5
|
|
| 22.04 LTS jammy |
Fixed 3.6.0-1ubuntu1.5
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Local |
| Attack complexity | Low |
| Privileges required | Low |
| User interaction | Required |
| Scope | Unchanged |
| Confidentiality | High |
| Integrity impact | None |
| Availability impact | High |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-7601-1
- libarchive vulnerabilities
- 26 June 2025