CVE-2025-5915
Publication date 9 June 2025
Last updated 26 June 2025
Ubuntu priority
Cvss 3 Severity Score
Description
A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| libarchive | 25.10 questing | 
                                Fixed 3.7.7-0ubuntu3 
                                
                               | 
| 25.04 plucky | 
                                Fixed 3.7.7-0ubuntu2.3 
                                
                               | |
| 24.04 LTS noble | 
                                Fixed 3.7.2-2ubuntu0.5 
                                
                               | |
| 22.04 LTS jammy | 
                                Fixed 3.6.0-1ubuntu1.5 
                                
                               | |
| 20.04 LTS focal | 
                                Needs evaluation 
                                
                               | |
| 18.04 LTS bionic | 
                                Needs evaluation 
                                
                               | |
| 16.04 LTS xenial | 
                                Needs evaluation 
                                
                               | |
| 14.04 LTS trusty | 
                                Needs evaluation 
                                
                               | 
Severity score breakdown
| Parameter | Value | 
|---|---|
| Base score |  | 
| Attack vector | Local | 
| Attack complexity | Low | 
| Privileges required | Low | 
| User interaction | Required | 
| Scope | Unchanged | 
| Confidentiality | Low | 
| Integrity impact | None | 
| Availability impact | Low | 
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L | 
References
Related Ubuntu Security Notices (USN)
- USN-7601-1
- libarchive vulnerabilities
- 26 June 2025