REDHAT-BUG-2370861: Integer Overflow
Published Jun 6, 2025
·Updated
In libarchive before 3.8.0, an integer overflow in the archivereadformatrarseekdata() function may lead to a double free problem.
Affected Software
1 affected component
Libarchive libarchive<3.8.0
Event History
Jun 6, 2025
Data Sourced
via Red Hat·06:03 PM
DescriptionSeverityAffected Software
Aug 5, 57583
Event
via Red Hat·08:40 AM
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2370861?
The severity of REDHAT-BUG-2370861 is critical due to the potential for a double free vulnerability.
2
How do I fix REDHAT-BUG-2370861?
To fix REDHAT-BUG-2370861, you should upgrade to libarchive version 3.8.0 or later.
3
What software versions are affected by REDHAT-BUG-2370861?
REDHAT-BUG-2370861 affects libarchive versions prior to 3.8.0.
4
What is the main issue with REDHAT-BUG-2370861?
The main issue with REDHAT-BUG-2370861 is an integer overflow in the archive_read_format_rar_seek_data() function.
5
Can REDHAT-BUG-2370861 be exploited remotely?
Yes, REDHAT-BUG-2370861 could potentially be exploited remotely if the affected software is exposed to untrusted input.