Skip to content

Conversation

@urielcos
Copy link

Updates

  • Affected products
  • Description
  • Source code location
  • Summary

Comments
On the official issue libarchive/libarchive#2559 seen in the repo, the error is mentioned to be introduced in 3.7.5
libarchive/libarchive@2d8a576 and fixed in 3.8.0 libarchive/libarchive@565b5ae

Also, the redhat advisory for a lower version used in the os 3.5.3 is marked as not affected https://access.redhat.com/security/cve/cve-2024-48615.

Myself I have tried compiling lower versions and ran bsdtar as seen in this POC https://github.com/88Sanghy88/crash-test and couldnt get it reproduced except for the affected versions.

@github-actions github-actions bot changed the base branch from main to urielcos/advisory-improvement-6476 November 27, 2025 08:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants