Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2025-11855

Опубликовано: 11 мая 2025
Источник: fstec
CVSS3: 3.9
CVSS2: 3.2
EPSS Низкий

Описание

Уязвимость библиотеки архивирования Libarchive связана с выходом операции за границы буфера в памяти. Эксплуатация уязвимости может позволить нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании

Вендор

Red Hat Inc.
Сообщество свободного программного обеспечения
ООО «Ред Софт»
ООО «РусБИТех-Астра»
АО «ИВК»
Canonical Ltd.
Fedora Project
АО «НППКТ»
АО «Лаборатория Касперского»

Наименование ПО

Red Hat Enterprise Linux
Debian GNU/Linux
РЕД ОС
Astra Linux Special Edition
Альт 8 СП
Red Hat OpenShift Container Platform
Ubuntu
Fedora
libarchive
ОСОН ОСнова Оnyx
In-Vehicle Operating System
Kaspersky Industrial CyberSecurity for Networks

Версия ПО

8 (Red Hat Enterprise Linux)
12 (Debian GNU/Linux)
7.3 (РЕД ОС)
1.7 (Astra Linux Special Edition)
4.7 (Astra Linux Special Edition)
- (Альт 8 СП)
4 (Red Hat OpenShift Container Platform)
22.04 LTS (Ubuntu)
9 (Red Hat Enterprise Linux)
22.10 (Ubuntu)
22.04 (Ubuntu)
41 (Fedora)
24.04 LTS (Ubuntu)
1.8 (Astra Linux Special Edition)
24.10 (Ubuntu)
42 (Fedora)
10 (Red Hat Enterprise Linux)
до 3.8.0 (libarchive)
до 3.1 (ОСОН ОСнова Оnyx)
1 (In-Vehicle Operating System)
4.0.1.222 (Kaspersky Industrial CyberSecurity for Networks)
4.3.0.231 (Kaspersky Industrial CyberSecurity for Networks)

Тип ПО

Операционная система
Прикладное ПО информационных систем
Программное средство защиты

Операционные системы и аппаратные платформы

Red Hat Inc. Red Hat Enterprise Linux 8
Сообщество свободного программного обеспечения Debian GNU/Linux 12
ООО «Ред Софт» РЕД ОС 7.3
ООО «РусБИТех-Астра» Astra Linux Special Edition 1.7
ООО «РусБИТех-Астра» Astra Linux Special Edition 4.7
АО «ИВК» Альт 8 СП -
Canonical Ltd. Ubuntu 22.04 LTS
Red Hat Inc. Red Hat Enterprise Linux 9
Canonical Ltd. Ubuntu 22.10
Canonical Ltd. Ubuntu 22.04
Fedora Project Fedora 41
Canonical Ltd. Ubuntu 24.04 LTS
ООО «РусБИТех-Астра» Astra Linux Special Edition 1.8
Canonical Ltd. Ubuntu 24.10
Fedora Project Fedora 42
Red Hat Inc. Red Hat Enterprise Linux 10
АО «НППКТ» ОСОН ОСнова Оnyx до 3.1
Red Hat Inc. In-Vehicle Operating System 1

Уровень опасности уязвимости

Низкий уровень опасности (базовая оценка CVSS 2.0 составляет 3.2)
Низкий уровень опасности (базовая оценка CVSS 3.1 составляет 3.9)

Возможные меры по устранению уязвимости

В условиях отсутствия обновлений безопасности от производителя рекомендуется придерживаться "Рекомендаций по безопасной настройке операционных систем LINUX", изложенных в методическом документе ФСТЭК России, утверждённом 25 декабря 2022 года.
Использование рекомендаций:
Для Libarchive:
https://github.com/libarchive/libarchive/commit/a612bf62f86a6faa47bd57c52b94849f0a404d8c
Для ОС Astra Linux:
обновить пакет libarchive до 3.8.1-0astra1 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se18-bulletin-2025-0811SE18
Для ОС Astra Linux:
обновить пакет libarchive до 3.8.1-0astra1 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0923SE17
Для РедОС:
http://repo.red-soft.ru/redos/7.3c/x86_64/updates/
Для ОС Astra Linux:
обновить пакет libarchive до 3.8.1-0astra1 или более высокой версии, используя рекомендации производителя: https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1020SE47
Для ОС Альт 8 СП: установка обновления из публичного репозитория программного средства: https://altsp.su/obnovleniya-bezopasnosti/
Для ОСОН ОСнова Onyx: Обновление программного обеспечения libarchive до версии 3.6.2-1+deb12u3.osnova3u1
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2025-5915
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2025-5915
Для Ubuntu:
https://ubuntu.com/security/CVE-2025-5915
Для Fedora:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2025-5915
Для Kaspersky Industrial CyberSecurity for Networks:
следовать рекомендациям по повышению защищенности системы, изложенным в документации на программное изделие
https://support.kaspersky.ru/kics-for-networks/4.5?page=main

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 6%
0.00163
Низкий

3.9 Low

CVSS3

3.2 Low

CVSS2

Связанные уязвимости

CVSS3: 9.8
redos
10 месяцев назад

Множественные уязвимости libarchive

CVSS3: 6.6
ubuntu
около 1 года назад

A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.

CVSS3: 6.6
redhat
около 1 года назад

A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.

CVSS3: 6.6
nvd
около 1 года назад

A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions.

CVSS3: 3.9
msrc
11 месяцев назад

Libarchive: heap buffer over read in copy_from_lzss_window() at archive_read_support_format_rar.c

EPSS

Процентиль: 6%
0.00163
Низкий

3.9 Low

CVSS3

3.2 Low

CVSS2