CVE-2025-60753
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-11-05
Last updated on: 2026-02-04
Assigner: MITRE
Description
Description
An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| libarchive | bsdtar | * |
| libarchive | libarchive | to 3.8.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-835 | The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop. |
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in libarchive bsdtar before version 3.8.1 in the apply_substitution function when processing crafted -s substitution rules. It can cause unbounded memory allocation, which may lead to a denial of service through an Out-of-Memory crash.
How can this vulnerability impact me? :
The vulnerability can cause the affected application to consume excessive memory, potentially crashing the system or service due to an Out-of-Memory condition, resulting in denial of service.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70