CVE-2025-8194

There is a defect in the CPython tarfile module affecting the TarFile extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. 

This vulnerability can be mitigated by including the following patch after importing the tarfile module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
PSFCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA-ADPADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python2.7
plucky
dne
noble
dne
jammy
Fixed 2.7.18-13ubuntu1.5+esm7
released
focal
Fixed 2.7.18-1~20.04.7+esm8
released
bionic
Fixed 2.7.17-1~18.04ubuntu1.13+esm12
released
xenial
Fixed 2.7.12-1ubuntu0~16.04.18+esm17
released
trusty
Fixed 2.7.6-8ubuntu0.6+esm26
released
python3.4
plucky
dne
noble
dne
jammy
dne
trusty
Fixed 3.4.3-1ubuntu1~14.04.7+esm16
released
python3.5
plucky
dne
noble
dne
jammy
dne
xenial
Fixed 3.5.2-2ubuntu0~16.04.13+esm19
released
trusty
Fixed 3.5.2-2ubuntu0~16.04.4~14.04.1+esm7
released
python3.6
plucky
dne
noble
dne
jammy
dne
bionic
Fixed 3.6.9-1~18.04ubuntu1.13+esm6
released
python3.7
plucky
dne
noble
dne
jammy
dne
bionic
Fixed 3.7.5-2ubuntu1~18.04.2+esm7
released
python3.8
plucky
dne
noble
dne
jammy
dne
focal
Fixed 3.8.10-0ubuntu1~20.04.18+esm2
released
bionic
Fixed 3.8.0-3ubuntu1~18.04.2+esm6
released
python3.9
plucky
dne
noble
dne
jammy
dne
focal
Fixed 3.9.5-3ubuntu0~20.04.1+esm6
released
python3.10
plucky
dne
noble
dne
jammy
Fixed 3.10.12-1~22.04.11
released
python3.11
plucky
dne
noble
dne
jammy
Fixed 3.11.0~rc1-1~22.04.1~esm5
released
python3.12
plucky
dne
noble
Fixed 3.12.3-1ubuntu0.8
released
jammy
dne
python3.13
plucky
Fixed 3.13.3-1ubuntu0.3
released
noble
dne
jammy
dne
python3.14
plucky
dne
noble
dne
jammy
dne