Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:15024 - Security Advisory
Issued:
2025-09-02
Updated:
2025-09-02

RHSA-2025:15024 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libarchive security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libarchive is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libarchive programming library can create and read several different streaming archive formats, including GNU tar, cpio, and ISO 9660 CD-ROM images. Libarchive is used notably in the bsdtar utility, scripting language bindings such as python-libarchive, and several popular desktop file managers.

Security Fix(es):

  • libarchive: Double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c (CVE-2025-5914)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x

Fixes

  • BZ - 2370861 - CVE-2025-5914 libarchive: Double free at archive_read_format_rar_seek_data() in archive_read_support_format_rar.c

CVEs

  • CVE-2025-5914

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
libarchive-3.5.3-5.el9_2.src.rpm SHA-256: 3450f3415e952bfaa29e9a62054c0f8db055cde1b7e27b2c732bdee51615fd5b
x86_64
bsdcat-debuginfo-3.5.3-5.el9_2.i686.rpm SHA-256: 2a6d51c9203636514bd070a46158970beccca5b7e59d2764b12adf24c578992c
bsdcat-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: 3f134a9ff9395b82922b62d8db1007c19d1bc16e7ace4bc39dd7d76cd972a963
bsdcat-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: 3f134a9ff9395b82922b62d8db1007c19d1bc16e7ace4bc39dd7d76cd972a963
bsdcpio-debuginfo-3.5.3-5.el9_2.i686.rpm SHA-256: b2f75069ad872140fff9496436182d67634439e77e978fb91abd01ce3deda11c
bsdcpio-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: d1d3ae22720bc8f5672edaa45f6e48a12969f44a992222c4ee55e049cc98f38c
bsdcpio-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: d1d3ae22720bc8f5672edaa45f6e48a12969f44a992222c4ee55e049cc98f38c
bsdtar-3.5.3-5.el9_2.x86_64.rpm SHA-256: 6c2243b275ba7fa9dc9d1691b6378fa475fc3b7a587c1ded733add4e019ca21e
bsdtar-debuginfo-3.5.3-5.el9_2.i686.rpm SHA-256: 38a9a973e8ad0267adf47854cca21d2832c8b5314601a7bd4adab754b6126c89
bsdtar-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: dcedffee2c2e4f0b586359bb7510b381ec5ef2f4228dd4e239406991a3a57a0a
bsdtar-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: dcedffee2c2e4f0b586359bb7510b381ec5ef2f4228dd4e239406991a3a57a0a
libarchive-3.5.3-5.el9_2.i686.rpm SHA-256: e8438f8199925d94911b6aca97fae3ced756ebfee6250c2c4b17a515b211af12
libarchive-3.5.3-5.el9_2.x86_64.rpm SHA-256: 0a7e1666cb0aabbc12c2d50fd41e05829b5cab303cdbd43976fbfcb740a96fa5
libarchive-debuginfo-3.5.3-5.el9_2.i686.rpm SHA-256: 26985bd2985fa400c8dd0721de4ac286b4e3e4d342588b2d5266edfa9a94100a
libarchive-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: 42565b253753072b79351fab5e17b4ad6a405979233a7ec80847def238e091c3
libarchive-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: 42565b253753072b79351fab5e17b4ad6a405979233a7ec80847def238e091c3
libarchive-debugsource-3.5.3-5.el9_2.i686.rpm SHA-256: f937aa74c16e83517ff34eabc5c100a307d610ce77d16c4907f8f857f5fc7c61
libarchive-debugsource-3.5.3-5.el9_2.x86_64.rpm SHA-256: f047de11dc2011ff6d7f872e5922e61203cc29adbd6345fa4f78519b9eccd97d
libarchive-debugsource-3.5.3-5.el9_2.x86_64.rpm SHA-256: f047de11dc2011ff6d7f872e5922e61203cc29adbd6345fa4f78519b9eccd97d

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
libarchive-3.5.3-5.el9_2.src.rpm SHA-256: 3450f3415e952bfaa29e9a62054c0f8db055cde1b7e27b2c732bdee51615fd5b
ppc64le
bsdcat-debuginfo-3.5.3-5.el9_2.ppc64le.rpm SHA-256: ffb0bcb07811cabd9ae9e3fdc556d03a332de45c8f363aa74c55caef94ffcd57
bsdcat-debuginfo-3.5.3-5.el9_2.ppc64le.rpm SHA-256: ffb0bcb07811cabd9ae9e3fdc556d03a332de45c8f363aa74c55caef94ffcd57
bsdcpio-debuginfo-3.5.3-5.el9_2.ppc64le.rpm SHA-256: f168dab3f8d852af9a6e0a5a5ab48fd2bf92ba8a8ae35181418d98e34d7613bf
bsdcpio-debuginfo-3.5.3-5.el9_2.ppc64le.rpm SHA-256: f168dab3f8d852af9a6e0a5a5ab48fd2bf92ba8a8ae35181418d98e34d7613bf
bsdtar-3.5.3-5.el9_2.ppc64le.rpm SHA-256: e1735debbb5abc13892bd7ee46349f9607e89472f99b5962bf07deae06f0690f
bsdtar-debuginfo-3.5.3-5.el9_2.ppc64le.rpm SHA-256: ceb9cd53a0ae16e5468c6b718d372a7875e2d4bb11d532a92507d5c281a89576
bsdtar-debuginfo-3.5.3-5.el9_2.ppc64le.rpm SHA-256: ceb9cd53a0ae16e5468c6b718d372a7875e2d4bb11d532a92507d5c281a89576
libarchive-3.5.3-5.el9_2.ppc64le.rpm SHA-256: e393f6f2186da832dc8d17880f7a0b154322b4a89e07a085a9f6f66070e5a4a2
libarchive-debuginfo-3.5.3-5.el9_2.ppc64le.rpm SHA-256: 54b776864ca3f79a0d29e89cd2e55c3a443e953ed5a0322e314bfc5eab172970
libarchive-debuginfo-3.5.3-5.el9_2.ppc64le.rpm SHA-256: 54b776864ca3f79a0d29e89cd2e55c3a443e953ed5a0322e314bfc5eab172970
libarchive-debugsource-3.5.3-5.el9_2.ppc64le.rpm SHA-256: 185fc5532cdfb94556910417fa6acef96e483fd6cafffa1b7a9dc91d3ba1dd18
libarchive-debugsource-3.5.3-5.el9_2.ppc64le.rpm SHA-256: 185fc5532cdfb94556910417fa6acef96e483fd6cafffa1b7a9dc91d3ba1dd18

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
libarchive-3.5.3-5.el9_2.src.rpm SHA-256: 3450f3415e952bfaa29e9a62054c0f8db055cde1b7e27b2c732bdee51615fd5b
x86_64
bsdcat-debuginfo-3.5.3-5.el9_2.i686.rpm SHA-256: 2a6d51c9203636514bd070a46158970beccca5b7e59d2764b12adf24c578992c
bsdcat-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: 3f134a9ff9395b82922b62d8db1007c19d1bc16e7ace4bc39dd7d76cd972a963
bsdcat-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: 3f134a9ff9395b82922b62d8db1007c19d1bc16e7ace4bc39dd7d76cd972a963
bsdcpio-debuginfo-3.5.3-5.el9_2.i686.rpm SHA-256: b2f75069ad872140fff9496436182d67634439e77e978fb91abd01ce3deda11c
bsdcpio-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: d1d3ae22720bc8f5672edaa45f6e48a12969f44a992222c4ee55e049cc98f38c
bsdcpio-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: d1d3ae22720bc8f5672edaa45f6e48a12969f44a992222c4ee55e049cc98f38c
bsdtar-3.5.3-5.el9_2.x86_64.rpm SHA-256: 6c2243b275ba7fa9dc9d1691b6378fa475fc3b7a587c1ded733add4e019ca21e
bsdtar-debuginfo-3.5.3-5.el9_2.i686.rpm SHA-256: 38a9a973e8ad0267adf47854cca21d2832c8b5314601a7bd4adab754b6126c89
bsdtar-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: dcedffee2c2e4f0b586359bb7510b381ec5ef2f4228dd4e239406991a3a57a0a
bsdtar-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: dcedffee2c2e4f0b586359bb7510b381ec5ef2f4228dd4e239406991a3a57a0a
libarchive-3.5.3-5.el9_2.i686.rpm SHA-256: e8438f8199925d94911b6aca97fae3ced756ebfee6250c2c4b17a515b211af12
libarchive-3.5.3-5.el9_2.x86_64.rpm SHA-256: 0a7e1666cb0aabbc12c2d50fd41e05829b5cab303cdbd43976fbfcb740a96fa5
libarchive-debuginfo-3.5.3-5.el9_2.i686.rpm SHA-256: 26985bd2985fa400c8dd0721de4ac286b4e3e4d342588b2d5266edfa9a94100a
libarchive-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: 42565b253753072b79351fab5e17b4ad6a405979233a7ec80847def238e091c3
libarchive-debuginfo-3.5.3-5.el9_2.x86_64.rpm SHA-256: 42565b253753072b79351fab5e17b4ad6a405979233a7ec80847def238e091c3
libarchive-debugsource-3.5.3-5.el9_2.i686.rpm SHA-256: f937aa74c16e83517ff34eabc5c100a307d610ce77d16c4907f8f857f5fc7c61
libarchive-debugsource-3.5.3-5.el9_2.x86_64.rpm SHA-256: f047de11dc2011ff6d7f872e5922e61203cc29adbd6345fa4f78519b9eccd97d
libarchive-debugsource-3.5.3-5.el9_2.x86_64.rpm SHA-256: f047de11dc2011ff6d7f872e5922e61203cc29adbd6345fa4f78519b9eccd97d

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
libarchive-3.5.3-5.el9_2.src.rpm SHA-256: 3450f3415e952bfaa29e9a62054c0f8db055cde1b7e27b2c732bdee51615fd5b
aarch64
bsdcat-debuginfo-3.5.3-5.el9_2.aarch64.rpm SHA-256: 21a094523aaa9eec72e51a74a5bd8e66bdc336ff345dd5652aa33ee55c281011
bsdcat-debuginfo-3.5.3-5.el9_2.aarch64.rpm SHA-256: 21a094523aaa9eec72e51a74a5bd8e66bdc336ff345dd5652aa33ee55c281011
bsdcpio-debuginfo-3.5.3-5.el9_2.aarch64.rpm SHA-256: 51795977fa3683f28ef6ef1e717342e83b30bed307eef43c0a2fff6427e26213
bsdcpio-debuginfo-3.5.3-5.el9_2.aarch64.rpm SHA-256: 51795977fa3683f28ef6ef1e717342e83b30bed307eef43c0a2fff6427e26213
bsdtar-3.5.3-5.el9_2.aarch64.rpm SHA-256: 63790855da19b0782b2b7a6c7be425eba0564cbf42549c37761edf7e585a4126
bsdtar-debuginfo-3.5.3-5.el9_2.aarch64.rpm SHA-256: 9f38030f11e0e4ba0fda75f15daf05ca298adeb717587547f1d8a20bb4791437
bsdtar-debuginfo-3.5.3-5.el9_2.aarch64.rpm SHA-256: 9f38030f11e0e4ba0fda75f15daf05ca298adeb717587547f1d8a20bb4791437
libarchive-3.5.3-5.el9_2.aarch64.rpm SHA-256: d0ac75368e3f24b423faa9f84ed4f8968c6e19da588be18b29cbcdf569097809
libarchive-debuginfo-3.5.3-5.el9_2.aarch64.rpm SHA-256: a92dae4e6b28ca7b36f45a5efa72978f5f9ab90fc6cc71564cd5a99cbf0f1468
libarchive-debuginfo-3.5.3-5.el9_2.aarch64.rpm SHA-256: a92dae4e6b28ca7b36f45a5efa72978f5f9ab90fc6cc71564cd5a99cbf0f1468
libarchive-debugsource-3.5.3-5.el9_2.aarch64.rpm SHA-256: bea25bb7ed5fd6515abca5243780c74d49b9850803c1f9bb822ec6e11f97ef7e
libarchive-debugsource-3.5.3-5.el9_2.aarch64.rpm SHA-256: bea25bb7ed5fd6515abca5243780c74d49b9850803c1f9bb822ec6e11f97ef7e

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
libarchive-3.5.3-5.el9_2.src.rpm SHA-256: 3450f3415e952bfaa29e9a62054c0f8db055cde1b7e27b2c732bdee51615fd5b
s390x
bsdcat-debuginfo-3.5.3-5.el9_2.s390x.rpm SHA-256: eb201bf907ee09821e92b2a824b8abb02e8313dc83ce97fd154815d0d96e1302
bsdcat-debuginfo-3.5.3-5.el9_2.s390x.rpm SHA-256: eb201bf907ee09821e92b2a824b8abb02e8313dc83ce97fd154815d0d96e1302
bsdcpio-debuginfo-3.5.3-5.el9_2.s390x.rpm SHA-256: 98e46aba92351816b54feba24355c875205a28d38dd9fab18e80b1be07619e75
bsdcpio-debuginfo-3.5.3-5.el9_2.s390x.rpm SHA-256: 98e46aba92351816b54feba24355c875205a28d38dd9fab18e80b1be07619e75
bsdtar-3.5.3-5.el9_2.s390x.rpm SHA-256: 52ac8ce42d0a1c4036bd52a6bd99ad940e3ef54f6335527be1b3ee3fd074d0ca
bsdtar-debuginfo-3.5.3-5.el9_2.s390x.rpm SHA-256: a664e683bd91ecf4ce7b2d272a2a66268f9d7f820f13d975a402b2fcf39151b9
bsdtar-debuginfo-3.5.3-5.el9_2.s390x.rpm SHA-256: a664e683bd91ecf4ce7b2d272a2a66268f9d7f820f13d975a402b2fcf39151b9
libarchive-3.5.3-5.el9_2.s390x.rpm SHA-256: 1c87e5783dee79f96b3a66261d4665e11fd7f40ae0339627cfe73cf2ebaeacbc
libarchive-debuginfo-3.5.3-5.el9_2.s390x.rpm SHA-256: c429f22bdf026464dfbcb80690d42753e7f3bcb62f331f286c37c12faf1686ee
libarchive-debuginfo-3.5.3-5.el9_2.s390x.rpm SHA-256: c429f22bdf026464dfbcb80690d42753e7f3bcb62f331f286c37c12faf1686ee
libarchive-debugsource-3.5.3-5.el9_2.s390x.rpm SHA-256: c6985d7e5cd0414eaf958674d0c21bdf5159c23005ad336186273fc11e9b7d50
libarchive-debugsource-3.5.3-5.el9_2.s390x.rpm SHA-256: c6985d7e5cd0414eaf958674d0c21bdf5159c23005ad336186273fc11e9b7d50

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility