High severity7.8NVD Advisory· Published Oct 10, 2024· Updated Jun 17, 2026
CVE-2024-48958
CVE-2024-48958
Description
execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:libarchive:libarchive:*:*:*:*:*:*:*:*range: >=3.6.0,<3.7.5
- (no CPE)
- (no CPE)range: <3.7.5
- osv-coords5 versionspkg:rpm/opensuse/libarchive&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/libarchive&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/libarchive&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP6pkg:rpm/suse/libarchive&distro=SUSE%20Linux%20Micro%206.0pkg:rpm/suse/libarchive&distro=SUSE%20Linux%20Micro%206.1
< 3.7.2-150600.3.9.1+ 4 more
- (no CPE)range: < 3.7.2-150600.3.9.1
- (no CPE)range: < 3.7.2-150600.3.9.1
- (no CPE)range: < 3.7.2-150600.3.9.1
- (no CPE)range: < 3.6.2-4.1
- (no CPE)range: < 3.7.4-slfo.1.1_2.1
Patches
Vulnerability mechanics
References
8- github.com/libarchive/libarchive/compare/v3.7.4...v3.7.5nvdPatch
- github.com/libarchive/libarchive/pull/2148nvdPatch
- github.com/terrynini/CVE-Reports/tree/main/CVE-2024-48958nvdExploitThird Party Advisory
- seclists.org/fulldisclosure/2025/Apr/11nvd
- seclists.org/fulldisclosure/2025/Apr/12nvd
- seclists.org/fulldisclosure/2025/Apr/13nvd
- seclists.org/fulldisclosure/2025/Apr/4nvd
- seclists.org/fulldisclosure/2025/Apr/8nvd
News mentions
0No linked articles in our index yet.