REDHAT-BUG-2370865: Low severity Libarchive libarchive vulnerability
Published Jun 6, 2025
·Updated
In libarchive before 3.8.0, because size of filter block can sometime be larger then lzss window, a heap buffer over read may occur.
Affected Software
1 affected component
Libarchive libarchive<3.8.0
Event History
Jun 6, 2025
Data Sourced
via Red Hat·06:25 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2370865?
The severity of REDHAT-BUG-2370865 is categorized as critical due to a potential heap buffer over read vulnerability.
2
How do I fix REDHAT-BUG-2370865?
To fix REDHAT-BUG-2370865, you should upgrade libarchive to version 3.8.0 or later.
3
What systems are affected by REDHAT-BUG-2370865?
REDHAT-BUG-2370865 affects all systems using libarchive versions prior to 3.8.0.
4
What kind of vulnerability is REDHAT-BUG-2370865?
REDHAT-BUG-2370865 is a heap buffer over read vulnerability resulting from the inappropriate handling of filter block sizes.
5
When was REDHAT-BUG-2370865 reported?
REDHAT-BUG-2370865 was reported prior to the release of libarchive version 3.8.0 and is publicly documented in the Red Hat Bugzilla.