USN-7454-1: libarchive vulnerabilities
It was discovered that the libarchive bsdunzip utility incorrectly handled certain ZIP archive files. If a user or automated system were tricked into processing a specially crafted ZIP archive, an attacker could use this issue to cause libarchive to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-1632) It was discovered that libarchive incorrectly handled certain TAR archive files. If a user or automated system were tricked into processing a specially crafted TAR archive, an attacker could use this issue to cause libarchive to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2025-25724)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7454-1?
USN-7454-1 is classified as a critical vulnerability due to the potential for denial of service.
How do I fix USN-7454-1?
To fix USN-7454-1, update the libarchive package to version 3.7.7-0ubuntu2.1 or a later version.
Which Ubuntu versions are affected by USN-7454-1?
USN-7454-1 affects multiple Ubuntu versions including 20.04, 22.04, 24.04, and 25.04.
What are the potential consequences of exploiting USN-7454-1?
Exploiting USN-7454-1 can lead to application crashes and denial of service in systems using the affected libarchive utility.
Is there a workaround for USN-7454-1?
Currently, the best approach for USN-7454-1 is to apply the available updates, as no specific workaround is recommended.