Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-58183

Опубликовано: 29 окт. 2025
Источник: debian
EPSS Низкий

Описание

tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.25fixed1.25.2-1package
golang-1.24fixed1.24.8-1package
golang-1.24no-dsatrixiepackage
golang-1.23removedpackage
golang-1.19removedpackage
golang-1.19no-dsabookwormpackage
golang-1.15removedpackage
golang-1.15postponedbullseyepackage

Примечания

  • https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI/m/qZN5nc-mBgAJ

  • https://github.com/golang/go/issues/75677

  • https://github.com/golang/go/commit/2612dcfd3cb6dd73c76e14a24fe1a68e2708e4e3 (go1.25.2)

  • https://github.com/golang/go/commit/613e746327381d820759ebea6ce722720b343556 (go1.24.8)

EPSS

Процентиль: 2%
0.00015
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
27 дней назад

[archive/tar: unbounded allocation when parsing GNU sparse map]

CVSS3: 4.3
nvd
7 дней назад

tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.

msrc
6 дней назад

Unbounded allocation when parsing GNU sparse map in archive/tar

CVSS3: 3.3
github
7 дней назад

tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.

suse-cvrf
16 дней назад

Security update for go1.24

EPSS

Процентиль: 2%
0.00015
Низкий