tar.Reader does not set a maximum size on the number of...
Low severity
Unreviewed
Published
Oct 30, 2025
to the GitHub Advisory Database
•
Updated Oct 30, 2025
Description
Published by the National Vulnerability Database
Oct 29, 2025
Published to the GitHub Advisory Database
Oct 30, 2025
Last updated
Oct 30, 2025
tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.
References