CVE-2025-58183
Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
29/10/2025
Última modificación:
04/11/2025
Descripción
*** Pendiente de traducción *** tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.
Impacto
Puntuación base 3.x
4.30
Gravedad 3.x
MEDIA



