REDHAT-BUG-2370872: Integer Overflow
Published Jun 6, 2025
·Updated
In libarchive before 3.8.0, a warc archive that claims to have more than INT64MAX - 4 content bytes may lead to an integer overflow.
Affected Software
1 affected component
Libarchive libarchive<3.8.0
Event History
Jun 6, 2025
Data Sourced
via Red Hat·07:19 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2370872?
The severity of REDHAT-BUG-2370872 is classified as a potential critical vulnerability due to the integer overflow risk.
2
How do I fix REDHAT-BUG-2370872?
Updating libarchive to version 3.8.0 or later will resolve the vulnerability associated with REDHAT-BUG-2370872.
3
Who is affected by REDHAT-BUG-2370872?
Any systems using libarchive versions prior to 3.8.0 that process warc archives are affected by REDHAT-BUG-2370872.
4
What type of vulnerability is REDHAT-BUG-2370872?
REDHAT-BUG-2370872 is an integer overflow vulnerability that can lead to unexpected behavior when handling certain warc archives.
5
When was REDHAT-BUG-2370872 reported?
REDHAT-BUG-2370872 was reported alongside the release notes for libarchive that addressed the integer overflow issue.