Impact
A vulnerable implementation of libarchive can cause a heap-based buffer overflow (CWE-122) when parsing a tar archive that contains a malformed PAX extended header with a SUN.holesdata sparse-file attribute. A malicious archive can trigger an out-of-bounds read, leading to memory corruption that may result in denial of service or, if the overflow is exploitable, arbitrary code execution.
Affected Systems
This vulnerability affects any system that uses libarchive on Red Hat Enterprise Linux 6 through 10, Red Hat Hardened Images, and Red Hat OpenShift Container Platform 4. Because no specific package versions are listed, any installation of an unpatched libarchive on these platforms could be vulnerable.
Risk and Exploitability
The CVSS score of 3.9 indicates a low overall severity, and the EPSS score of less than 1% shows a very small likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attacks would require an attacker to supply a malicious tar archive to a process that extracts it; this attack vector is indirect, inferred from the fact that the flaw is triggered during archive parsing. Successful exploitation could cause service disruption via denial of service or, if the memory corruption enables execution of arbitrary code, compromise of the affected system.
OpenCVE Enrichment
Ubuntu USN