diff options
| author | Divya Chellam <divya.chellam@windriver.com> | 2025-07-08 15:08:17 +0530 |
|---|---|---|
| committer | Steve Sakoman <steve@sakoman.com> | 2025-07-14 08:37:40 -0700 |
| commit | 6b95583a823da8f676cab720d660b16bc29ff89e (patch) | |
| tree | d81b919f5d62dac896b43d342da1a17e41e656cb /meta/recipes-devtools/python/python3 | |
| parent | 6cc6cd3f8d2a981280ec5f90da699411c4a1a6c7 (diff) | |
| download | poky-6b95583a823da8f676cab720d660b16bc29ff89e.tar.gz | |
libarchive: fix CVE-2025-5916
A vulnerability has been identified in the libarchive library. This flaw
involves an integer overflow that can be triggered when processing a Web
Archive (WARC) file that claims to have more than INT64_MAX - 4 content
bytes. An attacker could craft a malicious WARC archive to induce this
overflow, potentially leading to unpredictable program behavior, memory
corruption, or a denial-of-service condition within applications that
process such archives using libarchive.
Reference:
https://security-tracker.debian.org/tracker/CVE-2025-5916
Upstream-patch:
https://github.com/libarchive/libarchive/commit/ef093729521fcf73fa4007d5ae77adfe4df42403
(From OE-Core rev: 0e939bf5fc7412c7357fcd7d8ae760f023ac40eb)
Signed-off-by: Divya Chellam <divya.chellam@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Diffstat (limited to 'meta/recipes-devtools/python/python3')
0 files changed, 0 insertions, 0 deletions
