CVE-2025-58183: Unbounded allocation when parsing GNU sparse map in archive/tar
tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.
Other sources
Unbounded allocation when parsing GNU sparse map in archive/tar
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 25.0.3-14 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.62.0-10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 24.0.9-19 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.57.0-17 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.55.0-26 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.14.4-7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.14.2-13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.22.3-17
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58183?
CVE-2025-58183 has a high severity rating due to its potential to cause significant memory exploitation.
How do I fix CVE-2025-58183?
To mitigate CVE-2025-58183, ensure you are using the latest version of GNU tar that includes the security patch.
What are the potential impacts of CVE-2025-58183?
CVE-2025-58183 can lead to memory exhaustion or denial of service by allowing malicious archives to consume excessive system resources.
Who is affected by CVE-2025-58183?
CVE-2025-58183 affects users of GNU tar, particularly those working with PAX sparse files.
How can I determine if my system is vulnerable to CVE-2025-58183?
You can check your installed version of GNU tar and compare it against known vulnerable versions listed in the vulnerability advisory.