CVE-2025-5918: Libarchive: reading past eof may be triggered for piped file streams
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
Other sources
App Store. A permissions issue was addressed with additional restrictions.
— Apple
AppleJPEG. The issue was addressed with improved bounds checks.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
AppleMobileFileIntegrity. A permissions issue was addressed with additional restrictions.
— Apple
AppleMobileFileIntegrity. The issue was addressed by adding additional logic.
— Apple
Credit
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-43539
- CVE-2025-43519
- CVE-2025-46289
- CVE-2025-43482
- CVE-2025-43517
- CVE-2025-46287
- CVE-2024-7264
- CVE-2025-9086
- CVE-2025-43518
- CVE-2025-43532
- CVE-2025-43512
- CVE-2025-46285
- CVE-2025-5918
- CVE-2025-43513
- CVE-2025-46276
- CVE-2025-43509
- CVE-2025-43538
- CVE-2025-43463
- CVE-2025-43416
- CVE-2025-43516
- CVE-2025-43530
- CVE-2025-43320
- CVE-2025-43522
- CVE-2025-43521
- CVE-2025-43523
- CVE-2025-43542
- CVE-2025-43527
- CVE-2025-46279
- CVE-2025-46311
- CVE-2025-46290
- CVE-2025-46292
- CVE-2025-43535
- CVE-2025-43541
- CVE-2025-43501
- CVE-2025-43536
- CVE-2025-43531
- CVE-2025-14174
- CVE-2025-43529
- CVE-2025-46288
- CVE-2025-46286
- CVE-2025-43537
- CVE-2025-43534
- CVE-2025-43475
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2025-43428
- CVE-2025-46277
- CVE-2025-46298
- CVE-2025-46299
- CVE-2025-43511
- CVE-2025-46297
- CVE-2025-46283
- CVE-2025-46281
- CVE-2025-43417
- CVE-2025-46278
- CVE-2025-43524
- CVE-2025-46291
- CVE-2025-43410
- CVE-2025-43526
- CVE-2024-8906
- CVE-2025-43514
- CVE-2025-46282
Frequently Asked Questions
What is the severity of CVE-2025-5918?
CVE-2025-5918 is classified as a medium severity vulnerability due to the potential for out-of-bounds reads.
How do I fix CVE-2025-5918?
To mitigate CVE-2025-5918, you should update the libarchive library to the latest patched version.
What are the potential impacts of CVE-2025-5918?
CVE-2025-5918 could lead to unpredictable behavior in applications using libarchive, including potential data leakage.
What software is affected by CVE-2025-5918?
CVE-2025-5918 affects all software that utilizes the libarchive library, particularly when using bsdtar.
How can I determine if CVE-2025-5918 is present in my system?
You can check for CVE-2025-5918 by reviewing the version of the libarchive library installed on your system.