PT-2025-42899 · Unknown+1 · Astral-Tokio-Tar+1

Published

2025-10-21

·

Updated

2026-05-06

·

CVE-2025-62518

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions astral-tokio-tar versions prior to 0.5.6 async-tar versions prior to 0.5.6 tokio-tar versions prior to 0.5.6
Description astral-tokio-tar, async-tar, and tokio-tar are vulnerable to a boundary parsing issue due to inconsistent handling of PAX/ustar headers. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances the stream position based on the ustar header size (often zero) instead of the PAX-specified size, leading to misinterpretation of file content as legitimate tar headers. This can allow attackers to smuggle additional archive entries. The vulnerability is exploitable when processing untrusted tar archives and may result in arbitrary code execution or credential exfiltration. The issue stems from the parser using the ustar size instead of the PAX override when calculating the file position. This vulnerability is also known as TARmageddon (CVE-2025-62518).
Recommendations Upgrade astral-tokio-tar to version 0.5.6 or newer. Upgrade async-tar to version 0.5.6 or newer. Upgrade tokio-tar to version 0.5.6 or newer.

Exploit

Fix

RCE

Type Confusion

Weakness Enumeration

Related Identifiers

BDU:2025-15219
CVE-2025-62518
GHSA-GCHP-Q4R4-X4FF
GHSA-J5GW-2VRG-8FGX
GHSA-W476-P2H3-79G9
OPENSUSE-SU-2025:15658-1
OPENSUSE-SU-2026:20026-1
RUSTSEC-2025-0110
RUSTSEC-2025-0111
SUSE-SU-2026:20077-1

Affected Products

Debian
Astral-Tokio-Tar