OSV-2025-258

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/karchive/OSV-2025-258.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2025-258
Published
2025-04-05T00:05:58.760780Z
Modified
2025-04-05T00:05:58.761154Z
Summary
Global-buffer-overflow in parseExtraField
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=408025088

Crash type: Global-buffer-overflow READ 1
Crash state:
parseExtraField
KZip::openArchive
KArchive::open
References

Affected packages

OSS-Fuzz / karchive

Package

Name
karchive
Purl
pkg:generic/karchive

Affected ranges

Type
GIT
Repo
https://invent.kde.org/frameworks/karchive.git
Events
Introduced
2bf86d9d8e078513cc5d9f00d8e95544d9990d6c
Fixed
281cf70c3c79cd1e62bdfb2b81e82177e1306853

Affected versions

v6.*
v6.13.0
v6.13.0-rc1
v6.14.0
v6.14.0-rc1

Ecosystem specific

{
    "severity": null
}

Database specific

source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/karchive/OSV-2025-258.yaml"
introduced_range
"eafaa3cfb5ddc5f3564fffdf45af4d5e02e87f40:9860bba9fc913559571bb99136eb4999bc7f04f9"
fixed_range
"2770b134b7c33d483368c880bdd70bf14bf08bab:281cf70c3c79cd1e62bdfb2b81e82177e1306853"