{"id":"AZL-69893","summary":"CVE-2025-60753 affecting package libarchive for versions less than 3.6.1-8","details":"An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).","modified":"2026-04-01T05:21:38.898647Z","published":"2025-11-05T16:15:40Z","upstream":["CVE-2025-60753"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-60753"}],"affected":[{"package":{"name":"libarchive","ecosystem":"Azure Linux:2","purl":"pkg:rpm/azure-linux/libarchive"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.1-8"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-69893.json"}}],"schema_version":"1.7.5"}