Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-32288

Опубликовано: 08 апр. 2026
Источник: debian
EPSS Низкий

Описание

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.26fixed1.26.2-1package
golang-1.25fixed1.25.9-1package
golang-1.24removedpackage
golang-1.24no-dsatrixiepackage
golang-1.19removedpackage
golang-1.19no-dsabookwormpackage
golang-1.15removedpackage
golang-1.15postponedbullseyepackage

Примечания

  • https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU

  • https://github.com/golang/go/issues/78301

  • Fixed by: https://github.com/golang/go/commit/a34b5e4d55e39efc9af0d803969e9399a553acf3 (go1.26.2)

  • Fixed by: https://github.com/golang/go/commit/82b0cdb7411ea2cf02d3a45e6983cc7c8c009d9e (go1.25.9)

EPSS

Процентиль: 21%
0.0029
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
4 месяца назад

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

CVSS3: 4.3
redhat
4 месяца назад

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

CVSS3: 5.5
nvd
4 месяца назад

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

CVSS3: 5.5
msrc
4 месяца назад

Unbounded allocation for old GNU sparse in archive/tar

CVSS3: 5.5
github
4 месяца назад

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

EPSS

Процентиль: 21%
0.0029
Низкий