{"id":"AZL-69866","summary":"CVE-2025-60753 affecting package libarchive for versions less than 3.7.7-4","details":"An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).","modified":"2026-04-01T05:21:38.135817Z","published":"2025-11-05T16:15:40Z","upstream":["CVE-2025-60753"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-60753"}],"affected":[{"package":{"name":"libarchive","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libarchive"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.7.7-4"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-69866.json"}}],"schema_version":"1.7.5"}