libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar. Exploitation envisions a marginally plausible scenario in which original-filename is obtained from an untrusted party. (original-filename is not derived from the input data.)
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Sep 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar. Exploitation envisions a marginally plausible scenario in which original-filename is obtained from an untrusted party. (original-filename is not derived from the input data.) | |
| First Time appeared |
Libarchive
Libarchive libarchive |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libarchive
Libarchive libarchive |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-14T00:10:51.769Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-64031
No data.
Status : Received
Published: 2026-09-14T01:16:26.190
Modified: 2026-09-14T01:16:26.190
Link: CVE-2025-64031
No data.
OpenCVE Enrichment
Updated: 2026-09-14T01:30:17Z
Weaknesses