CVE-2025-11579
ADVISORY - githubSummary
rardecode versions <= 2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.
Common Weakness Enumeration (CWE)
Memory Allocation with Excessive Size Value
Memory Allocation with Excessive Size Value
Memory Allocation with Excessive Size Value
NIST
3.9
CVSS SCORE
5.3mediumGitHub
3.9
CVSS SCORE
5.3mediumDebian
-
Ubuntu
2.8
CVSS SCORE
6.5mediumGoLang
-
Red Hat
3.9
CVSS SCORE
5.3mediumChainguard
CGA-2956-q3pw-5q5x
-
Chainguard
CGA-2qc6-pw5f-gp72
-
Chainguard
CGA-34pr-5wj3-qc68
-
Chainguard
CGA-3xfh-9mph-6xjq
-
Chainguard
CGA-532j-jfx3-f3v6
-
Chainguard
CGA-5hmq-fg36-2jmq
-
Chainguard
CGA-65w5-2299-vhvm
-
Chainguard
CGA-6j5w-485r-f53h
-
Chainguard
CGA-6wmh-4j2j-qh6g
-
Chainguard
CGA-7rr2-96c3-x8qj
-
Chainguard
CGA-9j6q-xp3r-7r4c
-
Chainguard
CGA-9vmq-9gg9-j9h2
-
Chainguard
CGA-chq2-3pvc-2h23
-
Chainguard
CGA-f6mw-cjgx-h4h8
-
Chainguard
CGA-f8x9-h6f5-pqch
-
Chainguard
CGA-fp7c-47cq-wjq7
-
Chainguard
CGA-fpj9-f3q6-7p7g
-
Chainguard
CGA-g7cw-v5px-r97f
-
Chainguard
CGA-gfwm-32fw-qx9m
-
Chainguard
CGA-jj32-pcw8-c662
-
Chainguard
CGA-mqmj-g5cc-rqq2
-
Chainguard
CGA-q5g6-vp8q-cj29
-
Chainguard
CGA-q77j-4w89-78jv
-
Chainguard
CGA-r733-9hhp-mx73
-
Chainguard
CGA-rpxm-3r99-33x6
-
Chainguard
CGA-vxwh-cwcx-qhmr
-
Chainguard
CGA-w5xh-5j4g-4r7r
-
Chainguard
CGA-w88r-9xmv-hhv8
-
Chainguard
CGA-x8h5-xx42-mr96
-
minimos
MINI-45ch-35qc-9fv4
-