Impact
A signed integer overflow occurs in the libarchive ZIP writer when encryption is enabled and the entry file size is close to the maximum 64‑bit value. The overflow can cause undefined behavior, leading to incorrect Zip64 extension decisions or memory corruption without providing any broader security impact.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux releases 10, 6, 7, 8, and 9, Red Hat Hardened Images, and Red Hat OpenShift Container Platform 4. All affected systems rely on the libarchive library in the format used for ZIP archives.
Risk and Exploitability
With a CVSS score of 2.9 and an EPSS score below 1%, the risk of exploitation is low and there is no record in the CISA KEV catalog. The likely attack path would require an attacker to supply a crafted ZIP archive with encryption enabled and a size near the 64‑bit maximum, which is highly specific and limited in scope. No remote code execution or privilege escalation is described in the CVE data.
OpenCVE Enrichment