Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32766

Опубликовано: 20 мар. 2026
Источник: redhat
CVSS3: 2.5
EPSS Низкий

Описание

astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.6 and earlier, malformed PAX extensions were silently skipped when parsing tar archives. This silent skipping (rather than rejection) of invalid PAX extensions could be used as a building block for a parser differential, for example by silently skipping a malformed GNU “long link” extension so that a subsequent parser would misinterpret the extension. In practice, exploiting this behavior in astral-tokio-tar requires a secondary misbehaving tar parser, i.e. one that insufficiently validates malformed PAX extensions and interprets them rather than skipping or erroring on them. This vulnerability is considered low-severity as it requires a separate vulnerability against any unrelated tar parser. This issue has been fixed in version 0.6.0.

A flaw was found in astral-tokio-tar, a software component for handling tar archives. This flaw causes malformed PAX (Portable Archive eXchange) extensions within an archive to be silently ignored. An attacker could leverage this to create a specially crafted archive that, when processed by astral-tokio-tar and then by another vulnerable tar program, could be interpreted differently. This 'parser differential' might lead to misinterpretation of the archive's contents, but it requires a separate vulnerability in the secondary tar program for exploitation.

Отчет

This is a LOW impact flaw in astral-tokio-tar where malformed PAX extensions are silently ignored, potentially leading to a parser differential. Exploitation requires a secondary, vulnerable tar program that misinterprets these extensions. Red Hat products are only affected if they integrate astral-tokio-tar with such a vulnerable secondary parser.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-operator-bundleFix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-builder-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-rhel9-operatorFix deferred
Red Hat Enterprise Linux 10trusteeFix deferred
Red Hat Enterprise Linux 10trustee-guest-componentsFix deferred
Red Hat Enterprise Linux 9trustee-guest-componentsFix deferred
Red Hat OpenShift Container Platform 4kata-containersFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2449371astral-tokio-tar: astral-tokio-tar: Potential archive misinterpretation via malformed PAX extensions

EPSS

Процентиль: 16%
0.00249
Низкий

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
5 месяцев назад

astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.6 and earlier, malformed PAX extensions were silently skipped when parsing tar archives. This silent skipping (rather than rejection) of invalid PAX extensions could be used as a building block for a parser differential, for example by silently skipping a malformed GNU “long link” extension so that a subsequent parser would misinterpret the extension. In practice, exploiting this behavior in astral-tokio-tar requires a secondary misbehaving tar parser, i.e. one that insufficiently validates malformed PAX extensions and interprets them rather than skipping or erroring on them. This vulnerability is considered low-severity as it requires a separate vulnerability against any unrelated tar parser. This issue has been fixed in version 0.6.0.

CVSS3: 5.3
nvd
5 месяцев назад

astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.6 and earlier, malformed PAX extensions were silently skipped when parsing tar archives. This silent skipping (rather than rejection) of invalid PAX extensions could be used as a building block for a parser differential, for example by silently skipping a malformed GNU “long link” extension so that a subsequent parser would misinterpret the extension. In practice, exploiting this behavior in astral-tokio-tar requires a secondary misbehaving tar parser, i.e. one that insufficiently validates malformed PAX extensions and interprets them rather than skipping or erroring on them. This vulnerability is considered low-severity as it requires a separate vulnerability against any unrelated tar parser. This issue has been fixed in version 0.6.0.

msrc
5 месяцев назад

astral-tokio-tar insufficiently validates PAX extensions during extraction

CVSS3: 5.3
debian
5 месяцев назад

astral-tokio-tar is a tar archive reading/writing library for async Ru ...

CVSS3: 5.3
github
5 месяцев назад

astral-tokio-tar insufficiently validates PAX extensions during extraction

EPSS

Процентиль: 16%
0.00249
Низкий

2.5 Low

CVSS3