CVE-2025-64031

NameCVE-2025-64031
Descriptionlibarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar. Exploitation envisions a marginally plausible scenario in which original-filename is obtained from an untrusted party. (original-filename is not derived from the input data.)
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libarchive (PTS)bookworm3.6.2-1+deb12u4fixed
bookworm (security)3.6.2-1+deb12u5fixed
trixie3.7.4-4+deb13u1fixed
forky, sid3.8.9-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libarchivesource(unstable)(not affected)

Notes

- libarchive <not-affected> (Vulnerable code never in a Debian released version)
https://github.com/libarchive/libarchive/pull/2734
Introduced with: https://github.com/libarchive/libarchive/commit/84ac71335fd7bc151be763dd525353c182b280b5 (v3.8.0)
Fixed by: https://github.com/libarchive/libarchive/commit/53e85224536a73600f6920f692c9d38e16753bd9 (v3.8.2)

Search for package or bug name: Reporting problems