CVE-2025-8194

EUVD-2025-22999
There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. 

This vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
PSFCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python2.7
bionic
Fixed 2.7.17-1~18.04ubuntu1.13+esm12
released
focal
Fixed 2.7.18-1~20.04.7+esm8
released
jammy
Fixed 2.7.18-13ubuntu1.5+esm7
released
noble
dne
plucky
dne
questing
dne
trusty
Fixed 2.7.6-8ubuntu0.6+esm26
released
xenial
Fixed 2.7.12-1ubuntu0~16.04.18+esm17
released
python3.4
jammy
dne
noble
dne
plucky
dne
questing
dne
trusty
Fixed 3.4.3-1ubuntu1~14.04.7+esm16
released
python3.5
jammy
dne
noble
dne
plucky
dne
questing
dne
trusty
Fixed 3.5.2-2ubuntu0~16.04.4~14.04.1+esm7
released
xenial
Fixed 3.5.2-2ubuntu0~16.04.13+esm19
released
python3.6
bionic
Fixed 3.6.9-1~18.04ubuntu1.13+esm6
released
jammy
dne
noble
dne
plucky
dne
questing
dne
python3.7
bionic
Fixed 3.7.5-2ubuntu1~18.04.2+esm7
released
jammy
dne
noble
dne
plucky
dne
questing
dne
python3.8
bionic
Fixed 3.8.0-3ubuntu1~18.04.2+esm6
released
focal
Fixed 3.8.10-0ubuntu1~20.04.18+esm2
released
jammy
dne
noble
dne
plucky
dne
questing
dne
python3.9
focal
Fixed 3.9.5-3ubuntu0~20.04.1+esm6
released
jammy
dne
noble
dne
plucky
dne
questing
dne
python3.10
jammy
Fixed 3.10.12-1~22.04.11
released
noble
dne
plucky
dne
questing
dne
python3.11
jammy
Fixed 3.11.0~rc1-1~22.04.1~esm5
released
noble
dne
plucky
dne
questing
dne
python3.12
jammy
dne
noble
Fixed 3.12.3-1ubuntu0.8
released
plucky
dne
questing
dne
python3.13
jammy
dne
noble
dne
plucky
Fixed 3.13.3-1ubuntu0.3
released
questing
Fixed 3.13.6-1
released
python3.14
jammy
dne
noble
dne
plucky
dne
questing
not-affected