UBUNTU-CVE-2025-5915

Source
https://ubuntu.com/security/CVE-2025-5915
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-5915.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-5915
Related
Published
2025-06-09T20:15:00Z
Modified
2025-06-26T17:20:59Z
Severity
  • 3.9 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L CVSS Calculator
Summary
[none]
Details

A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.

References

Affected packages

Ubuntu:Pro:14.04:LTS / libarchive

Package

Name
libarchive
Purl
pkg:deb/ubuntu/libarchive@3.1.2-7ubuntu2.8+esm3?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.1.2-5ubuntu1
3.1.2-7ubuntu1
3.1.2-7ubuntu2
3.1.2-7ubuntu2.1
3.1.2-7ubuntu2.2
3.1.2-7ubuntu2.3
3.1.2-7ubuntu2.4
3.1.2-7ubuntu2.6
3.1.2-7ubuntu2.7
3.1.2-7ubuntu2.8
3.1.2-7ubuntu2.8+esm1
3.1.2-7ubuntu2.8+esm3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / libarchive

Package

Name
libarchive
Purl
pkg:deb/ubuntu/libarchive@3.1.2-11ubuntu0.16.04.8+esm1?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.1.2-11build1
3.1.2-11ubuntu0.16.04.1
3.1.2-11ubuntu0.16.04.2
3.1.2-11ubuntu0.16.04.3
3.1.2-11ubuntu0.16.04.4
3.1.2-11ubuntu0.16.04.5
3.1.2-11ubuntu0.16.04.6
3.1.2-11ubuntu0.16.04.7
3.1.2-11ubuntu0.16.04.8
3.1.2-11ubuntu0.16.04.8+esm1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / libarchive

Package

Name
libarchive
Purl
pkg:deb/ubuntu/libarchive@3.2.2-3.1ubuntu0.7+esm1?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.2.2-3.1
3.2.2-3.1ubuntu0.1
3.2.2-3.1ubuntu0.2
3.2.2-3.1ubuntu0.3
3.2.2-3.1ubuntu0.4
3.2.2-3.1ubuntu0.5
3.2.2-3.1ubuntu0.6
3.2.2-3.1ubuntu0.7
3.2.2-3.1ubuntu0.7+esm1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:20.04:LTS / libarchive

Package

Name
libarchive
Purl
pkg:deb/ubuntu/libarchive@3.4.0-2ubuntu1.5?arch=source&distro=esm-infra/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.4.0-1
3.4.0-1build1
3.4.0-1ubuntu2
3.4.0-2ubuntu1
3.4.0-2ubuntu1.1
3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.3
3.4.0-2ubuntu1.4
3.4.0-2ubuntu1.5

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / libarchive

Package

Name
libarchive
Purl
pkg:deb/ubuntu/libarchive@3.6.0-1ubuntu1.5?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.0-1ubuntu1.5

Affected versions

3.*

3.4.3-2
3.4.3-2build1
3.5.2-1
3.5.2-1ubuntu1
3.6.0-1ubuntu1
3.6.0-1ubuntu1.1
3.6.0-1ubuntu1.2
3.6.0-1ubuntu1.3
3.6.0-1ubuntu1.4

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.6.0-1ubuntu1.5",
            "binary_name": "libarchive-dev"
        },
        {
            "binary_version": "3.6.0-1ubuntu1.5",
            "binary_name": "libarchive-tools"
        },
        {
            "binary_version": "3.6.0-1ubuntu1.5",
            "binary_name": "libarchive-tools-dbgsym"
        },
        {
            "binary_version": "3.6.0-1ubuntu1.5",
            "binary_name": "libarchive13"
        },
        {
            "binary_version": "3.6.0-1ubuntu1.5",
            "binary_name": "libarchive13-dbgsym"
        }
    ],
    "ubuntu_priority": "medium",
    "availability": "No subscription required"
}

Ubuntu:24.10 / libarchive

Package

Name
libarchive
Purl
pkg:deb/ubuntu/libarchive@3.7.4-1ubuntu0.3?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.7.4-1ubuntu0.3

Affected versions

3.*

3.7.2-2
3.7.2-2.1
3.7.4-1
3.7.4-1ubuntu0.1
3.7.4-1ubuntu0.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.7.4-1ubuntu0.3",
            "binary_name": "libarchive-dev"
        },
        {
            "binary_version": "3.7.4-1ubuntu0.3",
            "binary_name": "libarchive-tools"
        },
        {
            "binary_version": "3.7.4-1ubuntu0.3",
            "binary_name": "libarchive-tools-dbgsym"
        },
        {
            "binary_version": "3.7.4-1ubuntu0.3",
            "binary_name": "libarchive13t64"
        },
        {
            "binary_version": "3.7.4-1ubuntu0.3",
            "binary_name": "libarchive13t64-dbgsym"
        }
    ],
    "ubuntu_priority": "medium",
    "availability": "No subscription required"
}

Ubuntu:24.04:LTS / libarchive

Package

Name
libarchive
Purl
pkg:deb/ubuntu/libarchive@3.7.2-2ubuntu0.5?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.7.2-2ubuntu0.5

Affected versions

3.*

3.6.2-1ubuntu1
3.7.2-1ubuntu1
3.7.2-1ubuntu2
3.7.2-1.1ubuntu2
3.7.2-2
3.7.2-2ubuntu0.1
3.7.2-2ubuntu0.2
3.7.2-2ubuntu0.3
3.7.2-2ubuntu0.4

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.7.2-2ubuntu0.5",
            "binary_name": "libarchive-dev"
        },
        {
            "binary_version": "3.7.2-2ubuntu0.5",
            "binary_name": "libarchive-tools"
        },
        {
            "binary_version": "3.7.2-2ubuntu0.5",
            "binary_name": "libarchive-tools-dbgsym"
        },
        {
            "binary_version": "3.7.2-2ubuntu0.5",
            "binary_name": "libarchive13t64"
        },
        {
            "binary_version": "3.7.2-2ubuntu0.5",
            "binary_name": "libarchive13t64-dbgsym"
        }
    ],
    "ubuntu_priority": "medium",
    "availability": "No subscription required"
}

Ubuntu:25.04 / libarchive

Package

Name
libarchive
Purl
pkg:deb/ubuntu/libarchive@3.7.7-0ubuntu2.3?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.7.7-0ubuntu2.3

Affected versions

3.*

3.7.4-1
3.7.4-1ubuntu1
3.7.4-1.1
3.7.7-0ubuntu1
3.7.7-0ubuntu2
3.7.7-0ubuntu2.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.7.7-0ubuntu2.3",
            "binary_name": "libarchive-dev"
        },
        {
            "binary_version": "3.7.7-0ubuntu2.3",
            "binary_name": "libarchive-tools"
        },
        {
            "binary_version": "3.7.7-0ubuntu2.3",
            "binary_name": "libarchive-tools-dbgsym"
        },
        {
            "binary_version": "3.7.7-0ubuntu2.3",
            "binary_name": "libarchive13t64"
        },
        {
            "binary_version": "3.7.7-0ubuntu2.3",
            "binary_name": "libarchive13t64-dbgsym"
        }
    ],
    "ubuntu_priority": "medium",
    "availability": "No subscription required"
}