Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-8194

Опубликовано: 28 июл. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

РелизСтатусПримечание
devel

DNE

esm-apps/focal

released

2.7.18-1~20.04.7+esm8
esm-apps/jammy

released

2.7.18-13ubuntu1.5+esm7
esm-infra-legacy/trusty

released

2.7.6-8ubuntu0.6+esm26
esm-infra/bionic

released

2.7.17-1~18.04ubuntu1.13+esm12
esm-infra/xenial

released

2.7.12-1ubuntu0~16.04.18+esm17
jammy

needed

noble

DNE

plucky

DNE

questing

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

released

3.10.12-1~22.04.11
noble

DNE

plucky

DNE

questing

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/jammy

released

3.11.0~rc1-1~22.04.1~esm5
jammy

needed

noble

DNE

plucky

DNE

questing

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

released

3.12.3-1ubuntu0.8
plucky

DNE

questing

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

released

3.13.6-1
jammy

DNE

noble

DNE

plucky

released

3.13.3-1ubuntu0.3
questing

released

3.13.6-1
upstream

released

3.13.6-1

Показывать по

РелизСтатусПримечание
devel

not-affected

3.14.0~rc2
jammy

DNE

noble

DNE

plucky

DNE

questing

not-affected

3.14.0~rc2
upstream

released

3.14.0rc2

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

released

3.4.3-1ubuntu1~14.04.7+esm16
jammy

DNE

noble

DNE

plucky

DNE

questing

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

released

3.5.2-2ubuntu0~16.04.4~14.04.1+esm7
esm-infra/xenial

released

3.5.2-2ubuntu0~16.04.13+esm19
jammy

DNE

noble

DNE

plucky

DNE

questing

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

released

3.6.9-1~18.04ubuntu1.13+esm6
jammy

DNE

noble

DNE

plucky

DNE

questing

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

released

3.7.5-2ubuntu1~18.04.2+esm7
jammy

DNE

noble

DNE

plucky

DNE

questing

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

released

3.8.0-3ubuntu1~18.04.2+esm6
esm-infra/focal

released

3.8.10-0ubuntu1~20.04.18+esm2
jammy

DNE

noble

DNE

plucky

DNE

questing

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

released

3.9.5-3ubuntu0~20.04.1+esm6
jammy

DNE

noble

DNE

plucky

DNE

questing

DNE

upstream

needs-triage

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
3 месяца назад

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVSS3: 7.5
nvd
3 месяца назад

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVSS3: 7.5
debian
3 месяца назад

There is a defect in the CPython \u201ctarfile\u201d module affecting ...

suse-cvrf
около 2 месяцев назад

Security update for python

suse-cvrf
около 2 месяцев назад

Security update for python311

7.5 High

CVSS3

Уязвимость CVE-2025-8194