CVE Tools

Libarchive

87 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Libarchive, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Libarchive CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Libarchive CVEs per month
MonthCVEs
2024-102
2024-110
2024-120
2025-010
2025-022
2025-032
2025-040
2025-050
2025-065
2025-070
2025-080
2025-090
2025-100
2025-111
2025-120
2026-010
2026-020
2026-034
2026-041
2026-050
2026-060
2026-070
2026-080
2026-091

Severity

How the 87 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical33%
  • High3439%
  • Medium4451%
  • Low67%

Latest CVEs

The 15 most recently published vulnerabilities affecting Libarchive.

  1. CVE-2025-64031libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA...2.5
  2. CVE-2026-5745Libarchive: a null pointer dereference vulnerability exists in the acl parser of libarchive5.5
  3. CVE-2026-5121Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing7.5
  4. CVE-2026-4426Libarchive: libarchive: denial of service via malformed iso file processing6.5
  5. CVE-2026-4424Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing7.5
  6. CVE-2026-4111Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive7.5
  7. CVE-2025-60753An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory a...5.5
  8. CVE-2025-5914Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c7.8
  9. CVE-2025-5917Libarchive: off by one error in build_ustar_entry_name() at archive_write_set_format_pax.c2.8
  10. CVE-2025-5918Libarchive: reading past eof may be triggered for piped file streams3.9
  11. CVE-2025-5916Libarchive: integer overflow while reading warc files at archive_read_support_format_warc.c3.9
  12. CVE-2025-5915Libarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c6.6
  13. CVE-2024-48615Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.7.5
  14. CVE-2025-25724list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that...4.0
  15. CVE-2025-1632libarchive bsdunzip.c list null pointer dereference3.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store