Libarchive
87 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Libarchive, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Libarchive CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 2 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 2 |
| 2025-03 | 2 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 5 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 1 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 4 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 87 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High34
- Medium44
- Low6
Latest CVEs
The 15 most recently published vulnerabilities affecting Libarchive.
- CVE-2025-64031libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA...2.5
- CVE-2026-5745Libarchive: a null pointer dereference vulnerability exists in the acl parser of libarchive5.5
- CVE-2026-5121Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing7.5
- CVE-2026-4426Libarchive: libarchive: denial of service via malformed iso file processing6.5
- CVE-2026-4424Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing7.5
- CVE-2026-4111Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive7.5
- CVE-2025-60753An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory a...5.5
- CVE-2025-5914Libarchive: double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c7.8
- CVE-2025-5917Libarchive: off by one error in build_ustar_entry_name() at archive_write_set_format_pax.c2.8
- CVE-2025-5918Libarchive: reading past eof may be triggered for piped file streams3.9
- CVE-2025-5916Libarchive: integer overflow while reading warc files at archive_read_support_format_warc.c3.9
- CVE-2025-5915Libarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c6.6
- CVE-2024-48615Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.7.5
- CVE-2025-25724list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return value, which can lead to a denial of service or unspecified other impact via a crafted TAR archive that...4.0
- CVE-2025-1632libarchive bsdunzip.c list null pointer dereference3.3
Product grouping is registry-driven, with AI assist and human review. How it works