VDB
BDU%3A2025-10932
BDU%3A2025-10932
PUBLISHED
CVSS 10 CRITICAL
Уязвимость функции archive_read_format_rar_seek_data() библиотеки Libarchive, позволяющая нарушителю выполнить произвольный код и вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical Ltd., Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», ООО «РусБИТех-Астра», АО «ИВК», АО «СберТех», ООО «НЦПР» | Ubuntu, Red Hat Enterprise Linux, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), Альт 8 СП (запись в едином реестре российских программ №4305), АЛЬТ СП 10, Platform V SberLinux OS Server (запись в едином реестре российских программ №18785), libarchive, МСВСфера |
Timeline
- Sep 10, 2025 CVE Published
- Jan 27, 2026 CVE Updated
References
- https://wiki.astralinux.ru/astra-linux-se18-bulletin-2025-0811SE18 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://github.com/libarchive/libarchive/releases/tag/v3.8.0 advisory
- https://access.redhat.com/security/cve/cve-2025-5914 advisory
- https://security-tracker.debian.org/tracker/CVE-2025-5914 advisory
- https://altsp.su/obnovleniya-bezopasnosti/ advisory
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0923SE17 advisory
- https://ubuntu.com/security/CVE-2025-5914 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1020SE47 url
- https://errata.msvsphere-os.ru/definition/9/INFCSA-2025:14130?lang=ru url
- https://github.com/libarchive/libarchive/pull/2598 advisory