
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-25724 is a vulnerability discovered in libarchive through version 3.7.7. The vulnerability was disclosed on March 1, 2025, affecting the list_item_verbose function in tar/util.c. The issue stems from an unchecked strftime return value, which could potentially lead to security implications when processing TAR archives (NVD).
The vulnerability is classified as CWE-252 (Unchecked Return Value) with a CVSS v3.1 Base Score of 4.0 (MEDIUM). The CVSS vector string is CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L, indicating local access vector, high attack complexity, no privileges required, and no user interaction needed. The technical issue occurs specifically when processing TAR archives with a verbose value of 2, where a 100-byte buffer may not be sufficient for custom locales (NVD, Red Hat).
The vulnerability can lead to a denial of service condition or other unspecified impacts when processing specially crafted TAR archives. The impact is particularly relevant when using custom locales where the 100-byte buffer limitation becomes a security concern (NVD, Snyk).
The vulnerability requires local access and has high attack complexity. The probability of exploitation, according to EPSS data, is relatively low at 0.05% (19th percentile). A proof of concept exists demonstrating the vulnerability (Snyk).
As of the initial disclosure, there is no fixed version available for affected systems. Red Hat Enterprise Linux 9 has marked this vulnerability as 'Fix deferred'. The vulnerability affects multiple versions of libarchive in various distributions, including Debian bullseye, bookworm, and sid (Debian Tracker, Red Hat).
Fix availability across major Linux distributions and their releases.
OpenShift
openshift/ose-rhel-coreos-9
RHEL 8
libarchive.src
RHEL 9
:appstream:libarchive-0:3.5.3-5.el9_4.1.src
RHEL 10
libarchive-0:3.7.7-3.el10_0.src
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."