CVE-2025-5914
Executive Summary
CVE-2025-5914 exposes an integer overflow in libarchive's archive_read_format_rar_seek_data(), leading to a double‑free and memory corruption. Attackers can exploit this to execute arbitrary code or trigger a denial‑of‑service. The flaw is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2025-06-09T20:15:26.123 - Last Modified: 2026-09-09T03:17:20.877
Original Description: A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.
"Life is like a sewer. What you get out of it depends on what you put into it."
— Tom Lehrer