CVE-2025-58183

EUVD-2025-36731
tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CISA-ADPADP
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
Debian logo
Debian Releases
Debian Product
Codename
golang-1.15
bookworm
no-dsa
bullseye
vulnerable
trixie
no-dsa
golang-1.19
bookworm
vulnerable
bullseye
postponed
trixie
no-dsa
golang-1.24
bookworm
no-dsa
bullseye
postponed
forky
1.24.13-2
fixed
sid
1.24.13-2
fixed
trixie
no-dsa
golang-1.25
bookworm
no-dsa
bullseye
postponed
forky
1.25.7-2
fixed
sid
1.25.7-2
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang
jammy
dne
noble
dne
plucky
dne
questing
dne
golang-1.6
jammy
dne
noble
dne
plucky
dne
questing
dne
xenial
needs-triage
golang-1.8
bionic
needs-triage
jammy
dne
noble
dne
plucky
dne
questing
dne
golang-1.9
bionic
needs-triage
jammy
dne
noble
dne
plucky
dne
questing
dne
golang-1.10
bionic
needs-triage
jammy
dne
noble
dne
plucky
dne
questing
dne
trusty
needs-triage
xenial
needs-triage
golang-1.13
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
plucky
dne
questing
dne
xenial
needs-triage
golang-1.14
focal
needs-triage
jammy
dne
noble
dne
plucky
dne
questing
dne
golang-1.16
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
dne
plucky
dne
questing
dne
golang-1.17
jammy
needs-triage
noble
dne
plucky
dne
questing
dne
golang-1.18
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
plucky
dne
questing
dne
xenial
needs-triage
golang-1.20
focal
needs-triage
jammy
needs-triage
noble
dne
plucky
dne
questing
dne
golang-1.21
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
dne
questing
dne
golang-1.22
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
dne
questing
dne
golang-1.23
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
needs-triage
golang-1.24
jammy
dne
noble
dne
plucky
ignored
questing
needs-triage
golang-1.25
jammy
dne
noble
dne
plucky
dne
questing
needs-triage