CVE-2025-11579: Unauthorized access and subscription vulnerability in Boards
github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.
Other sources
github.com/nwaples/rardecode versions =2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.
— IBM
rardecode versions <= 2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.
— GitHub
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11579?
CVE-2025-11579 is categorized as a Denial of Service vulnerability due to Out Of Memory crashes.
How do I fix CVE-2025-11579?
To mitigate CVE-2025-11579, upgrade to a version of nwaples rardecode that is greater than 2.1.1.
What versions of nwaples rardecode are affected by CVE-2025-11579?
CVE-2025-11579 affects nwaples rardecode versions up to and including 2.1.1.
What type of attack does CVE-2025-11579 enable?
CVE-2025-11579 allows attackers to crash the system via specially crafted RAR files.
What is the impact of exploiting CVE-2025-11579?
Exploitation of CVE-2025-11579 can lead to a Denial of Service condition, making the application unusable.