Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:14828 - Security Advisory
Issued:
2025-08-28
Updated:
2025-08-28

RHSA-2025:14828 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libarchive security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libarchive is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libarchive programming library can create and read several different streaming archive formats, including GNU tar, cpio, and ISO 9660 CD-ROM images. Libarchive is used notably in the bsdtar utility, scripting language bindings such as python-libarchive, and several popular desktop file managers.

Security Fix(es):

  • libarchive: Double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c (CVE-2025-5914)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2370861 - CVE-2025-5914 libarchive: Double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c

CVEs

  • CVE-2025-5914

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
libarchive-3.1.2-14.el7_9.1.src.rpm SHA-256: ca23da6e93c1bc0631b776b82100c21a472bafee6e8711a56ab28c138a2ff697
x86_64
bsdcpio-3.1.2-14.el7_9.1.x86_64.rpm SHA-256: 78a74d32373ecf61e018d1a80f7ba8a14b82ab61eaf5c2128f2a32091e54e069
bsdtar-3.1.2-14.el7_9.1.x86_64.rpm SHA-256: a460ea6c6eccace474ae066a3d447a12751805e6b1f566344ae362b57701bb8e
libarchive-3.1.2-14.el7_9.1.i686.rpm SHA-256: 0a69ab20175f9c9804a0c70e1a2d0b7477a3b8aa0bd7ac6bddc1f3c6e8c2aec8
libarchive-3.1.2-14.el7_9.1.x86_64.rpm SHA-256: 1a59783ecd2494c4b974620dbb82dd69d3a09f4dcdebf8a61539f76e9d20caf9
libarchive-debuginfo-3.1.2-14.el7_9.1.i686.rpm SHA-256: 6ccdd6a38be57556698a3557fba78a00e73ca580286cf4565aa47baf2f4638e8
libarchive-debuginfo-3.1.2-14.el7_9.1.i686.rpm SHA-256: 6ccdd6a38be57556698a3557fba78a00e73ca580286cf4565aa47baf2f4638e8
libarchive-debuginfo-3.1.2-14.el7_9.1.x86_64.rpm SHA-256: e55c07f5bac24ef0f7dad2f41a0e287b1959bfd69c6a91e98a0066e725e1b6af
libarchive-debuginfo-3.1.2-14.el7_9.1.x86_64.rpm SHA-256: e55c07f5bac24ef0f7dad2f41a0e287b1959bfd69c6a91e98a0066e725e1b6af
libarchive-devel-3.1.2-14.el7_9.1.i686.rpm SHA-256: f47e990147d9f048aeff2e23779ab47bbe589704a136bfb9e929950bcd7c9f67
libarchive-devel-3.1.2-14.el7_9.1.x86_64.rpm SHA-256: cafb272f1ecc737503c0af7c5e412183a87ac6c89448ed7e74db01155ee26e9f

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
libarchive-3.1.2-14.el7_9.1.src.rpm SHA-256: ca23da6e93c1bc0631b776b82100c21a472bafee6e8711a56ab28c138a2ff697
s390x
bsdcpio-3.1.2-14.el7_9.1.s390x.rpm SHA-256: bea00ef6cbb260fc34bcca7e7437abcb3ceb8e715fb4802b1d5b855b422e36f7
bsdtar-3.1.2-14.el7_9.1.s390x.rpm SHA-256: edb7a1c519d6518a59549e2224b7feca0a37f20154bb16cb491741afdc1cebe3
libarchive-3.1.2-14.el7_9.1.s390.rpm SHA-256: ee82f344449eac8f066cc1d765b6d5645cfb08da3b1574315b1719de66547a7a
libarchive-3.1.2-14.el7_9.1.s390x.rpm SHA-256: d0d126b54e93578748a51346d3f52e7895c1171290cc7880c8a2ea9bf5bc7afc
libarchive-debuginfo-3.1.2-14.el7_9.1.s390.rpm SHA-256: d07cbae71a15f03a7633bf6ab55ea034941bebfcece6f2765c779d180976fabd
libarchive-debuginfo-3.1.2-14.el7_9.1.s390.rpm SHA-256: d07cbae71a15f03a7633bf6ab55ea034941bebfcece6f2765c779d180976fabd
libarchive-debuginfo-3.1.2-14.el7_9.1.s390x.rpm SHA-256: 3ebca814592c8a5dfed3cbf3da62f753bcce7497c4dfb456608ef1778306ad96
libarchive-debuginfo-3.1.2-14.el7_9.1.s390x.rpm SHA-256: 3ebca814592c8a5dfed3cbf3da62f753bcce7497c4dfb456608ef1778306ad96
libarchive-devel-3.1.2-14.el7_9.1.s390.rpm SHA-256: e0a8178b2440b5acad0c40b4cb76d4fd7ccf79a1cfdf778598ef273cb85d8791
libarchive-devel-3.1.2-14.el7_9.1.s390x.rpm SHA-256: b772fad26631f9e4c3fc28523626d805a0a09cd56121f5a71676350c9fdd45eb

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
libarchive-3.1.2-14.el7_9.1.src.rpm SHA-256: ca23da6e93c1bc0631b776b82100c21a472bafee6e8711a56ab28c138a2ff697
ppc64
bsdcpio-3.1.2-14.el7_9.1.ppc64.rpm SHA-256: e85b3b8b58a431bd943eace42915e87d111e5fc8c48c73edabbc3a9190bed209
bsdtar-3.1.2-14.el7_9.1.ppc64.rpm SHA-256: b05645b7843b1c6e42d016a8a4c48fc31f67b764f4bc82b78328a30d1d75a95d
libarchive-3.1.2-14.el7_9.1.ppc.rpm SHA-256: 2b9604003856e5dd771c5c0be2136e2da4ac3dfb04b39934ae26564377e6b02c
libarchive-3.1.2-14.el7_9.1.ppc64.rpm SHA-256: 2e7134fbd0dc02223b16084c6c341901561fcdf44cb55f8379a28b4861656a8d
libarchive-debuginfo-3.1.2-14.el7_9.1.ppc.rpm SHA-256: c005ee72c2a3a320ac7dcd0fb08a8e36eb9bde11a4d1840ddbfd57bc0a851d96
libarchive-debuginfo-3.1.2-14.el7_9.1.ppc.rpm SHA-256: c005ee72c2a3a320ac7dcd0fb08a8e36eb9bde11a4d1840ddbfd57bc0a851d96
libarchive-debuginfo-3.1.2-14.el7_9.1.ppc64.rpm SHA-256: 299318980b16d44c30793dce16dfc637410bf1a9e2459ae7ab950f7d663347e1
libarchive-debuginfo-3.1.2-14.el7_9.1.ppc64.rpm SHA-256: 299318980b16d44c30793dce16dfc637410bf1a9e2459ae7ab950f7d663347e1
libarchive-devel-3.1.2-14.el7_9.1.ppc.rpm SHA-256: 6f1f3d097d1717e0ac4658499191aa41a86f74c73300286654ab57283eaaac11
libarchive-devel-3.1.2-14.el7_9.1.ppc64.rpm SHA-256: 041a9e5e6eae5e2b98e4ab81ec443776050b601ee6a348d968efe49e73ba3641

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
libarchive-3.1.2-14.el7_9.1.src.rpm SHA-256: ca23da6e93c1bc0631b776b82100c21a472bafee6e8711a56ab28c138a2ff697
ppc64le
bsdcpio-3.1.2-14.el7_9.1.ppc64le.rpm SHA-256: 256ce6ffa4d4640f4a09d944d6e05ae5180235df09c1c503f537e44c820fb474
bsdtar-3.1.2-14.el7_9.1.ppc64le.rpm SHA-256: c22c59b9453f24a3df32a548b8b9ea0a3b0f5fd4cdf59b312f83a1c2a586bd9f
libarchive-3.1.2-14.el7_9.1.ppc64le.rpm SHA-256: d81519c6e68a7165c30094be36a225c0f1ed365c44c3ff70dc39e9d07bba323e
libarchive-debuginfo-3.1.2-14.el7_9.1.ppc64le.rpm SHA-256: 6901de6b4f5c6368b57158538038bd171fb266ff069fec61bbf168dd213b8a91
libarchive-debuginfo-3.1.2-14.el7_9.1.ppc64le.rpm SHA-256: 6901de6b4f5c6368b57158538038bd171fb266ff069fec61bbf168dd213b8a91
libarchive-devel-3.1.2-14.el7_9.1.ppc64le.rpm SHA-256: 7e2b359a551ff639aa9c679a16085249e70fc288ffa80477982b7e750e37bcdb

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility