CVE-2024-48615

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 28, 2025
Updated: Apr 14, 2025
CWE ID 476

Summary

CVE-2024-48615 is a newly identified vulnerability affecting libarchive versions 3.7.6 and older. This issue results in a Null Pointer Dereference (NPD) during the execution of the 'bsdtar' program, specifically in the function 'header_pax_extension' located at 'rchive_read_support_format_tar.c:1844:8'. Exploitation of this NPD vulnerability could potentially lead to arbitrary code execution or a denial-of-service attack, posing a significant threat to systems using the affected version of libarchive. Users are advised to update to the latest stable release as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share