CVE-2025-5915 is a heap buffer over-read vulnerability in the libarchive library, affecting various Red Hat products including Enterprise Linux and OpenShift Container Platform. This flaw, stemming from an oversized filter block exceeding the LZSS window, can lead to denial of service, data disclosure, or unpredictable program behavior. Rated Medium severity (CVSS 6.6), it requires local access and user interaction for exploitation, with potential for high impact on confidentiality and availability. Currently, there is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.8.0CPE matchmatch criteria | cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025Libarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c
Jun 10, 2025libarchive: Heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c
May 20, 2025