Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-62518

Опубликовано: 21 окт. 2025
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds.

astral-tokio-tar contains a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Not affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-operator-bundleNot affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-builder-rhel9Not affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-rhel9-operatorNot affected
Red Hat Enterprise Linux 10trustee-guest-componentsAffected
Red Hat Enterprise Linux 9trustee-guest-componentsAffected
Red Hat OpenShift Container Platform 4kata-containersWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-843
https://bugzilla.redhat.com/show_bug.cgi?id=2405382astral-tokio-tar: astral-tokio-tar Vulnerable to PAX Header Desynchronization

EPSS

Процентиль: 5%
0.00018
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
5 месяцев назад

astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds.

CVSS3: 8.1
nvd
5 месяцев назад

astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds.

msrc
5 месяцев назад

astral-tokio-tar Vulnerable to PAX Header Desynchronization

CVSS3: 8.1
debian
5 месяцев назад

astral-tokio-tar is a tar archive reading/writing library for async Ru ...

CVSS3: 8.1
github
5 месяцев назад

astral-tokio-tar Vulnerable to PAX Header Desynchronization

EPSS

Процентиль: 5%
0.00018
Низкий

8.1 High

CVSS3