Description
microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy. Any application that calls these functions with an externally-influenced filename longer than 99 characters (e.g. when archiving user-supplied or attacker-controlled filenames) triggers a stack buffer overflow.
Published: 2026-08-05
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

microtar exposes a stack buffer overflow in the mtar_write_file_header() and mtar_write_dir_header() functions, which copy a supplied entry name into a 100‑byte buffer using an unchecked strcpy. The overflow occurs whenever a filename longer than 99 characters is processed, corrupting the stack frame and allowing an attacker to overwrite the return address. The vulnerability is classified as CWE‑121 and provides a straightforward path to execute code with the privileges of the running process. If the process runs with elevated rights, the impact can extend to privilege escalation. Affected systems The vendor/product rxi:microtar is the source of the flaw. No specific version information is supplied, so any release that incorporates the original unbounded strcpy remains vulnerable. Applications that embed microtar to create archives—including those that accept user‑supplied or attacker‑controlled filenames—are also impacted. Based on the description, it is inferred that any usage of these functions with an externally influenced filename longer than 99 characters can trigger the overflow. Risk and exploitability With a CVSS score of 9.8 the vulnerability is rated critical, and the EPSS score is not listed, which indicates that no public data is currently available about exploitation frequency. The lack of bounds checking creates a simple exploitation route: provide a long filename either locally when creating an archive or remotely if the archiving capability is exposed over a network. Successful exploitation yields arbitrary local code execution; if the software runs with elevated privileges, attacker‑controlled code could also achieve privilege escalation. The vulnerability is not present in CISA’s KEV catalog.

Affected Systems

The repository rxi:microtar is the vendor and product affected. No version list was supplied, so any release that still contains the original source from GitHub with the unbounded strcpy is vulnerable. Applications that embed microtar and process user‑supplied or attacker‑controlled filenames during archive creation are also impacted.

Risk and Exploitability

With a CVSS score of 9.8 the vulnerability is classified as critical. The EPSS score is not available, but the lack of bounds checking provides a straightforward exploitation path on any system running a vulnerable build. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires controlling the filename argument, which could be achieved either locally when a user creates an archive, or remotely if the archiving functionality is exposed over a network. A successful exploit would likely grant the attacker arbitrary local code execution, and if the process runs with elevated privileges, privilege escalation could follow.

Generated by OpenCVE AI on August 5, 2026 at 15:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace microtar with a version that bounds‑checks the filename length or patch the source to enforce a 99‑byte limit.
  • Validate or truncate all filenames before passing them to mtar_write_file_header() or mtar_write_dir_header() to ensure they do not exceed 99 characters.
  • Compile applications that use microtar with stack protection options such as –fstack-protector and enable address space layout randomization to increase exploitation difficulty.

Generated by OpenCVE AI on August 5, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Rxi
Rxi microtar
Vendors & Products Rxi
Rxi microtar

Wed, 05 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy. Any application that calls these functions with an externally-influenced filename longer than 99 characters (e.g. when archiving user-supplied or attacker-controlled filenames) triggers a stack buffer overflow.
Title microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir_header()
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TuranSec

Published:

Updated: 2026-08-05T15:54:12.444Z

Reserved: 2026-08-05T12:23:34.967Z

Link: CVE-2026-71267

cve-icon Vulnrichment

Updated: 2026-08-05T15:54:09.311Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T15:30:17Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow