Memory disclosure and crashes via oversized RAR filter
Published Jun 9, 2025 · Updated Sep 1, 2026
Heap buffer over-read in libarchive 3.6.0 through 3.7.9 allows local users to crash applications or disclose memory via a crafted RAR archive. copy_from_lzss_window accepts a filter block larger than the LZSS dictionary window and passes the excessive length to memcpy, reading beyond the heap allocation. Exploitation requires a user or consuming application to process the malicious archive; reported consequences are process crashes and adjacent-memory disclosure.
Summary
What happened
Heap buffer over-read in libarchive 3.6.0 through 3.7.9 allows local users to crash applications or disclose memory via a crafted RAR archive. copy_from_lzss_window accepts a filter block larger than the LZSS dictionary window and passes the excessive length to memcpy, reading beyond the heap allocation. Exploitation requires a user or consuming application to process the malicious archive; reported consequences are process crashes and adjacent-memory disclosure.
The record
- CVE
- CVE-2025-5915
- Published
- Jun 9, 2025
- Updated
- Sep 1, 2026
- Vendor
- 389 Directory Server
- Product
- Red Hat Enterprise Linux 10
- Classifications
- CWE-122, T1204.002
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Jun 9, 2025CVE publishedPublication date reported by the CVE source.
- Sep 1, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Affected versions are unavailable in this record. Check the vendor advisory for version and patch details.
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
- copy_from_lzss_window heap-over-read PoC archiveproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo