CVE-2025-58183

EUVD-2025-36731
tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
Debian logo
Debian Releases
Debian Product
Codename
golang-1.15
bullseye
postponed
golang-1.19
bookworm
no-dsa
golang-1.24
trixie
no-dsa
golang-1.25
forky
1.25.10-1
fixed
sid
1.25.10-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
golang-1.6
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
xenial
needs-triage
golang-1.8
bionic
needs-triage
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
golang-1.9
bionic
needs-triage
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
golang-1.10
bionic
needs-triage
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
trusty
needs-triage
xenial
needs-triage
golang-1.13
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
plucky
dne
questing
dne
resolute
dne
xenial
ignored
golang-1.14
focal
needs-triage
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
golang-1.16
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
golang-1.17
jammy
needs-triage
noble
dne
plucky
dne
questing
dne
resolute
dne
golang-1.18
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
plucky
dne
questing
dne
resolute
dne
xenial
ignored
golang-1.20
focal
needs-triage
jammy
needs-triage
noble
dne
plucky
dne
questing
dne
resolute
dne
golang-1.21
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
dne
questing
dne
resolute
dne
golang-1.22
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
dne
questing
dne
resolute
dne
golang-1.23
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
needs-triage
resolute
needs-triage
golang-1.24
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
needs-triage
resolute
needs-triage
golang-1.25
jammy
dne
noble
dne
plucky
dne
questing
needs-triage
resolute
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
buildah
RHEL 9
2:1.41.6-1.el9_7
fixed
buildah-tests
RHEL 9
2:1.41.6-1.el9_7
fixed
delve
RHEL 9
0:1.25.2-1.el9_7
fixed
go-toolset
RHEL 9
0:1.25.3-1.el9_7
fixed
golang
RHEL 9
0:1.25.3-1.el9_7
fixed
golang-bin
RHEL 9
0:1.25.3-1.el9_7
fixed
golang-docs
RHEL 9
0:1.25.3-1.el9_7
fixed
golang-misc
RHEL 9
0:1.25.3-1.el9_7
fixed
golang-race
RHEL 9
0:1.25.3-1.el9_7
fixed
golang-src
RHEL 9
0:1.25.3-1.el9_7
fixed
golang-tests
RHEL 9
0:1.25.3-1.el9_7
fixed
grafana
RHEL 8
0:9.2.10-26.el8_10
fixed
RHEL 8.2 AUS
0:6.3.6-9.el8_2
fixed
RHEL 9
0:10.2.6-17.el9_7
fixed
grafana-azure-monitor
RHEL 8.2 AUS
0:6.3.6-9.el8_2
fixed
grafana-cloudwatch
RHEL 8.2 AUS
0:6.3.6-9.el8_2
fixed
grafana-elasticsearch
RHEL 8.2 AUS
0:6.3.6-9.el8_2
fixed
grafana-graphite
RHEL 8.2 AUS
0:6.3.6-9.el8_2
fixed
grafana-influxdb
RHEL 8.2 AUS
0:6.3.6-9.el8_2
fixed
grafana-loki
RHEL 8.2 AUS
0:6.3.6-9.el8_2
fixed
grafana-mssql
RHEL 8.2 AUS
0:6.3.6-9.el8_2
fixed
grafana-mysql
RHEL 8.2 AUS
0:6.3.6-9.el8_2
fixed
grafana-opentsdb
RHEL 8.2 AUS
0:6.3.6-9.el8_2
fixed
grafana-postgres
RHEL 8.2 AUS
0:6.3.6-9.el8_2
fixed
grafana-prometheus
RHEL 8.2 AUS
0:6.3.6-9.el8_2
fixed
grafana-selinux
RHEL 8
0:9.2.10-26.el8_10
fixed
RHEL 9
0:10.2.6-17.el9_7
fixed
grafana-stackdriver
RHEL 8.2 AUS
0:6.3.6-9.el8_2
fixed
image-builder
RHEL 9
0:31-2.el9_7
fixed
osbuild-composer
RHEL 8
0:101.4-2.el8_10
fixed
RHEL 8.4 AUS
0:28.7-4.el8_4
fixed
RHEL 8.6 AUS
0:46.3-4.el8_6
fixed
RHEL 8.6 E4S
0:46.3-4.el8_6
fixed
RHEL 8.6 TUS
0:46.3-4.el8_6
fixed
RHEL 8.8 E4S
0:75-5.el8_8
fixed
RHEL 8.8 TUS
0:75-5.el8_8
fixed
RHEL 9
0:149-3.el9_7
fixed
osbuild-composer-core
RHEL 8
0:101.4-2.el8_10
fixed
RHEL 8.4 AUS
0:28.7-4.el8_4
fixed
RHEL 8.6 AUS
0:46.3-4.el8_6
fixed
RHEL 8.6 E4S
0:46.3-4.el8_6
fixed
RHEL 8.6 TUS
0:46.3-4.el8_6
fixed
RHEL 8.8 E4S
0:75-5.el8_8
fixed
RHEL 8.8 TUS
0:75-5.el8_8
fixed
RHEL 9
0:149-3.el9_7
fixed
osbuild-composer-dnf-json
RHEL 8.6 AUS
0:46.3-4.el8_6
fixed
RHEL 8.6 E4S
0:46.3-4.el8_6
fixed
RHEL 8.6 TUS
0:46.3-4.el8_6
fixed
RHEL 8.8 E4S
0:75-5.el8_8
fixed
RHEL 8.8 TUS
0:75-5.el8_8
fixed
osbuild-composer-worker
RHEL 8
0:101.4-2.el8_10
fixed
RHEL 8.4 AUS
0:28.7-4.el8_4
fixed
RHEL 8.6 AUS
0:46.3-4.el8_6
fixed
RHEL 8.6 E4S
0:46.3-4.el8_6
fixed
RHEL 8.6 TUS
0:46.3-4.el8_6
fixed
RHEL 8.8 E4S
0:75-5.el8_8
fixed
RHEL 8.8 TUS
0:75-5.el8_8
fixed
RHEL 9
0:149-3.el9_7
fixed
podman
RHEL 9
6:5.6.0-9.el9_7
fixed
podman-docker
RHEL 9
6:5.6.0-9.el9_7
fixed
podman-plugins
RHEL 9
6:5.6.0-9.el9_7
fixed
podman-remote
RHEL 9
6:5.6.0-9.el9_7
fixed
podman-tests
RHEL 9
6:5.6.0-9.el9_7
fixed
skopeo
RHEL 9
2:1.20.0-2.el9_7
fixed
skopeo-tests
RHEL 9
2:1.20.0-2.el9_7
fixed