VYPR
Unrated severityNVD Advisory· Published Oct 14, 2022· Updated Feb 13, 2025

Unbounded memory consumption when reading headers in archive/tar

CVE-2022-2879

Description

Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.

Affected products

70

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.