REDHAT-BUG-2370877: Low severity Libarchive libarchive vulnerability
Published Jun 6, 2025
·Updated
In libarchive before 3.8.0, read past EOF may be triggered for piped archive streams leading to unintended consequences.
Affected Software
1 affected component
Libarchive libarchive<3.8.0
Event History
Jun 6, 2025
Data Sourced
via Red Hat·07:44 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2370877?
The severity of REDHAT-BUG-2370877 is classified as moderate due to potential unintended consequences from reading past EOF in piped archive streams.
2
How do I fix REDHAT-BUG-2370877?
To fix REDHAT-BUG-2370877, upgrade libarchive to version 3.8.0 or later.
3
What is the impact of REDHAT-BUG-2370877 on my system?
The impact of REDHAT-BUG-2370877 may include data corruption or unexpected behavior when handling piped archive streams.
4
Which versions of libarchive are affected by REDHAT-BUG-2370877?
libarchive versions prior to 3.8.0 are affected by REDHAT-BUG-2370877.
5
Is REDHAT-BUG-2370877 a known issue reported by users?
Yes, REDHAT-BUG-2370877 is a known issue that has been reported and documented in the Red Hat Bugzilla.