Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

openSUSE Leap 15.4: SUSE-SU-2025:02718-1: libarchive Moderate Issues Fixed

opensuse
Calendar Grey August 6, 2025
Dist Opensuse Esm H88
The recent openSUSE update resolves several moderate vulnerabilities in libarchive, addressing various security-related CVEs.
An update that solves five vulnerabilities can now be installed.

Description

This update for libarchive fixes the following issues:

* CVE-2025-5914: Fixed double free due to an integer overflow in the

archive_read_format_rar_seek_data() function (bsc#1244272)

* CVE-2025-5915: Fixed heap buffer over read in copy_from_lzss_window() at

archive_read_support_format_rar.c (bsc#1244273)

* CVE-2025-5916: Fixed integer overflow while reading warc files at

archive_read_support_format_warc.c (bsc#1244270)

* CVE-2025-5917: Fixed off by one error in build_ustar_entry_name() at

archive_write_set_format_pax.c (bsc#1244336)

* CVE-2025-5918: Fixed reading past EOF may be triggered for piped file

streams (bsc#1244279)

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Micro for Rancher 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2025-2718=1

* SUSE Linux Enterprise Micro 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2025-2718=1

* SUSE Linux Enterprise Micro for Rancher 5.4

zypper in -t patch SUSE-SLE-Micro-5.4-2025-2718=1

* SUSE Linux Enterprise Micro 5.4

zypper in -t patch SUSE-SLE-Micro-5.4-2025-2718=1

* SUSE Linux Enterprise Micro 5.5

zypper in -t patch SUSE-SLE-Micro-5.5-2025-2718=1

* openSUSE Leap 15.4

zypper in -t patch SUSE-2025-2718=1

Package List

* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)

* libarchive13-debuginfo-3.5.1-150400.3.21.1

* libarchive13-3.5.1-150400.3.21.1

* libarchive-debugsource-3.5.1-150400.3.21.1

* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)

* libarchive13-debuginfo-3.5.1-150400.3.21.1

* libarchive13-3.5.1-150400.3.21.1

* libarchive-debugsource-3.5.1-150400.3.21.1

* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)

* libarchive13-debuginfo-3.5.1-150400.3.21.1

* libarchive13-3.5.1-150400.3.21.1

* libarchive-debugsource-3.5.1-150400.3.21.1

* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)

* libarchive13-debuginfo-3.5.1-150400.3.21.1

* libarchive13-3.5.1-150400.3.21.1

* libarchive-debugsource-3.5.1-150400.3.21.1

* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)

* libarchive13-debuginfo-3.5.1-150400.3.21.1

* libarchive13-3.5.1-150400.3.21.1

* libarchive-debugsource-3.5.1-150400.3.21.1

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)

*...

Read the Full Advisory

References

* bsc#1244270

* bsc#1244272

* bsc#1244273

* bsc#1244279

* bsc#1244336

## References:

* https://www.suse.com/security/cve/CVE-2025-5914.html

* https://www.suse.com/security/cve/CVE-2025-5915.html

* https://www.suse.com/security/cve/CVE-2025-5916.html

* https://www.suse.com/security/cve/CVE-2025-5917.html

* https://www.suse.com/security/cve/CVE-2025-5918.html

* https://bugzilla.suse.com/show_bug.cgi?id=1244270

* https://bugzilla.suse.com/show_bug.cgi?id=1244272

* https://bugzilla.suse.com/show_bug.cgi?id=1244273

* https://bugzilla.suse.com/show_bug.cgi?id=1244279

* https://bugzilla.suse.com/show_bug.cgi?id=1244336

Announcement ID: SUSE-SU-2025:02718-1
Release Date: 2025-08-06T13:55:10Z
Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here