Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:14525 - Security Advisory
Issued:
2025-08-25
Updated:
2025-08-25

RHSA-2025:14525 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libarchive security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libarchive is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libarchive programming library can create and read several different streaming archive formats, including GNU tar, cpio, and ISO 9660 CD-ROM images. Libarchive is used notably in the bsdtar utility, scripting language bindings such as python-libarchive, and several popular desktop file managers.

Security Fix(es):

  • libarchive: Double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c (CVE-2025-5914)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.8 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64

Fixes

  • BZ - 2370861 - CVE-2025-5914 libarchive: Double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c

CVEs

  • CVE-2025-5914

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8

SRPM
libarchive-3.3.3-5.el8_8.1.src.rpm SHA-256: c396bcae60d1546d531a3a33601b686565cb38e5734c72270284127583875fd2
x86_64
bsdcat-debuginfo-3.3.3-5.el8_8.1.i686.rpm SHA-256: 64db57b52e801239544336fb2966fdb744d6361c2d75ff2cb929ca8caefe065c
bsdcat-debuginfo-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 71815cd01906d054e504007bcdc93193dddd4ae15f6b30870027c6754dd4340c
bsdcpio-debuginfo-3.3.3-5.el8_8.1.i686.rpm SHA-256: f638728103531435610f741ecfebc816188242560bf4567ab2b7c5270fbcb70c
bsdcpio-debuginfo-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 13fd26e58034987e3071cfeb4e281e68da817afb558f224ca38422cd916e065c
bsdtar-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 4d4493faeff782b8e912e199130136076f4955e227c860e6418b490bf11ebd1e
bsdtar-debuginfo-3.3.3-5.el8_8.1.i686.rpm SHA-256: 8a3616a0a653fc3989073e556a67a2dbe51504aceffe995b1a0378e5a749b83f
bsdtar-debuginfo-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 959c463f9759954ccf3e2443e4d12f3152d94c0df3eab9e4a6e382f6021b2953
libarchive-3.3.3-5.el8_8.1.i686.rpm SHA-256: 21fb90fdbfcd873338f27cd5e649914a7c0d61aabc7ee5497eec3ec698bf384b
libarchive-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: e2b2a2375daffd75044a33db22c60db32ef7b1127a7c6b26a09db2c74d07226d
libarchive-debuginfo-3.3.3-5.el8_8.1.i686.rpm SHA-256: e3887271c733800ff343a683ef37eb93fc5016e2b502400cc44d555a7cc21461
libarchive-debuginfo-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 65127178b2c25fe318de204d62c768688f268674f63dbe20dcc3bd45eb17658d
libarchive-debugsource-3.3.3-5.el8_8.1.i686.rpm SHA-256: c1543c67f11e07e518508fe740ac53482be3e4561dfb1c67dd10321852cb934b
libarchive-debugsource-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 6b4a8a9f94f0946e29b9a894851096b9150a490cd95259f79302242e67d07b1e

Red Hat Enterprise Linux Server - TUS 8.8

SRPM
libarchive-3.3.3-5.el8_8.1.src.rpm SHA-256: c396bcae60d1546d531a3a33601b686565cb38e5734c72270284127583875fd2
x86_64
bsdcat-debuginfo-3.3.3-5.el8_8.1.i686.rpm SHA-256: 64db57b52e801239544336fb2966fdb744d6361c2d75ff2cb929ca8caefe065c
bsdcat-debuginfo-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 71815cd01906d054e504007bcdc93193dddd4ae15f6b30870027c6754dd4340c
bsdcpio-debuginfo-3.3.3-5.el8_8.1.i686.rpm SHA-256: f638728103531435610f741ecfebc816188242560bf4567ab2b7c5270fbcb70c
bsdcpio-debuginfo-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 13fd26e58034987e3071cfeb4e281e68da817afb558f224ca38422cd916e065c
bsdtar-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 4d4493faeff782b8e912e199130136076f4955e227c860e6418b490bf11ebd1e
bsdtar-debuginfo-3.3.3-5.el8_8.1.i686.rpm SHA-256: 8a3616a0a653fc3989073e556a67a2dbe51504aceffe995b1a0378e5a749b83f
bsdtar-debuginfo-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 959c463f9759954ccf3e2443e4d12f3152d94c0df3eab9e4a6e382f6021b2953
libarchive-3.3.3-5.el8_8.1.i686.rpm SHA-256: 21fb90fdbfcd873338f27cd5e649914a7c0d61aabc7ee5497eec3ec698bf384b
libarchive-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: e2b2a2375daffd75044a33db22c60db32ef7b1127a7c6b26a09db2c74d07226d
libarchive-debuginfo-3.3.3-5.el8_8.1.i686.rpm SHA-256: e3887271c733800ff343a683ef37eb93fc5016e2b502400cc44d555a7cc21461
libarchive-debuginfo-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 65127178b2c25fe318de204d62c768688f268674f63dbe20dcc3bd45eb17658d
libarchive-debugsource-3.3.3-5.el8_8.1.i686.rpm SHA-256: c1543c67f11e07e518508fe740ac53482be3e4561dfb1c67dd10321852cb934b
libarchive-debugsource-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 6b4a8a9f94f0946e29b9a894851096b9150a490cd95259f79302242e67d07b1e

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8

SRPM
libarchive-3.3.3-5.el8_8.1.src.rpm SHA-256: c396bcae60d1546d531a3a33601b686565cb38e5734c72270284127583875fd2
ppc64le
bsdcat-debuginfo-3.3.3-5.el8_8.1.ppc64le.rpm SHA-256: 7bc1c1d8cdb2573b72754d3275e7cdaa6502dd1711ee1c83219786b50378d3c0
bsdcpio-debuginfo-3.3.3-5.el8_8.1.ppc64le.rpm SHA-256: 6bbe8873bf5c1e465e8917e11d64545014a55c97068bf62aca0c45ff3db3d59f
bsdtar-3.3.3-5.el8_8.1.ppc64le.rpm SHA-256: 2ded3a923ae68257fb0a94456ed93c7ec3317fdef616e7968ca3f5b5bf717392
bsdtar-debuginfo-3.3.3-5.el8_8.1.ppc64le.rpm SHA-256: 152dd3f1da8df06a18a5584887753344390e9f702968493db0a72c11690c1708
libarchive-3.3.3-5.el8_8.1.ppc64le.rpm SHA-256: 21832db30e9318fb8ebd0ab946df77e934c6a4b2eb7c87370cd35f113f8302c6
libarchive-debuginfo-3.3.3-5.el8_8.1.ppc64le.rpm SHA-256: 7fd0d552d50e46ebc7bc74302a6a139ee78932cc2cb00e06960f9b38ef9174e6
libarchive-debugsource-3.3.3-5.el8_8.1.ppc64le.rpm SHA-256: 6a7cde770eb04357aceddc6f736ee980416ca8c1bffe8a9a3b7454884c3d50ae

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8

SRPM
libarchive-3.3.3-5.el8_8.1.src.rpm SHA-256: c396bcae60d1546d531a3a33601b686565cb38e5734c72270284127583875fd2
x86_64
bsdcat-debuginfo-3.3.3-5.el8_8.1.i686.rpm SHA-256: 64db57b52e801239544336fb2966fdb744d6361c2d75ff2cb929ca8caefe065c
bsdcat-debuginfo-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 71815cd01906d054e504007bcdc93193dddd4ae15f6b30870027c6754dd4340c
bsdcpio-debuginfo-3.3.3-5.el8_8.1.i686.rpm SHA-256: f638728103531435610f741ecfebc816188242560bf4567ab2b7c5270fbcb70c
bsdcpio-debuginfo-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 13fd26e58034987e3071cfeb4e281e68da817afb558f224ca38422cd916e065c
bsdtar-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 4d4493faeff782b8e912e199130136076f4955e227c860e6418b490bf11ebd1e
bsdtar-debuginfo-3.3.3-5.el8_8.1.i686.rpm SHA-256: 8a3616a0a653fc3989073e556a67a2dbe51504aceffe995b1a0378e5a749b83f
bsdtar-debuginfo-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 959c463f9759954ccf3e2443e4d12f3152d94c0df3eab9e4a6e382f6021b2953
libarchive-3.3.3-5.el8_8.1.i686.rpm SHA-256: 21fb90fdbfcd873338f27cd5e649914a7c0d61aabc7ee5497eec3ec698bf384b
libarchive-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: e2b2a2375daffd75044a33db22c60db32ef7b1127a7c6b26a09db2c74d07226d
libarchive-debuginfo-3.3.3-5.el8_8.1.i686.rpm SHA-256: e3887271c733800ff343a683ef37eb93fc5016e2b502400cc44d555a7cc21461
libarchive-debuginfo-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 65127178b2c25fe318de204d62c768688f268674f63dbe20dcc3bd45eb17658d
libarchive-debugsource-3.3.3-5.el8_8.1.i686.rpm SHA-256: c1543c67f11e07e518508fe740ac53482be3e4561dfb1c67dd10321852cb934b
libarchive-debugsource-3.3.3-5.el8_8.1.x86_64.rpm SHA-256: 6b4a8a9f94f0946e29b9a894851096b9150a490cd95259f79302242e67d07b1e

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility