Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar. Exploitation envisions a marginally plausible scenario in which original-filename is obtained from an untrusted party. (original-filename is not derived from the input data.) | |
| First Time appeared |
Libarchive
Libarchive libarchive |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libarchive
Libarchive libarchive |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-14T00:10:51.769Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-64031
No data.
Status : Received
Published: 2026-09-14T01:16:26.190
Modified: 2026-09-14T01:16:26.190
Link: CVE-2025-64031
No data.
OpenCVE Enrichment
Updated: 2026-09-14T01:30:17Z
-
CWE-122
Heap-based Buffer Overflow