Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-11579

Опубликовано: 10 окт. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.

A memory exhaustion flaw has been discovered in the golang Rar Decode library (github.com/nwaples/rardecode). Affected versions did not limit the size of an archive and so an attacker could provide a crafted archive to a tool or service built on Rar decode which might consume more memory than available. This would lead to a program crash.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Serverlessopenshift-serverless-1/kn-plugin-event-sender-rhel8Fix deferred
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-central-db-rhel8Fix deferred
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-collector-rhel8Fix deferred
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Fix deferred
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-operator-bundleFix deferred
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-rhel8-operatorFix deferred
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-roxctl-rhel8Fix deferred
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-db-rhel8Fix deferred
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-db-slim-rhel8Fix deferred
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-scanner-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-789
https://bugzilla.redhat.com/show_bug.cgi?id=2403068github.com/nwaples/rardecode: RarDecode Out Of Memory Crash

EPSS

Процентиль: 28%
0.00349
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
11 месяцев назад

github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.

CVSS3: 5.3
nvd
11 месяцев назад

github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.

CVSS3: 5.3
debian
11 месяцев назад

github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dic ...

CVSS3: 5.3
github
11 месяцев назад

rardecode: DoS risk due to unrestricted RAR dictionary sizes

suse-cvrf
9 месяцев назад

Security update for hauler

EPSS

Процентиль: 28%
0.00349
Низкий

5.3 Medium

CVSS3