mediumVulnerability

GHSA-3pv8-6f4r-ffg2

### Summary When a tar stream contains multiple "header" entries prior to a file entry, tar-rs applies the PAX header (`x`) to the _next_ entry in the stream, regardless of type. For example, a stream of `x -> L -> file` (PAX, GNU longname, file) would result in `x`'s extensions being applied to `L` rather than to `file`. [Per POSIX pax](https://pubs.opengroup.org/onlinepubs/9799919799/utilities/pax.html), this is incorrect: a PAX header always applies to a file entry, not any intermediary entries. See the "pax Header Block" section for the specific prescription there. As a result of this, an attacker can contrive a tar containing a sequence of tar headers such that tar-rs applies the PAX header's `size` extension to the next header in sequence, effectively desynchronizing the stream and enabling tar-rs specific skippage/extraction of members. In other words, a file can be contrived to extract differently on tar-rs than on other tar parsers. ### PoC [This tar](https://github.com/user-attachments/files/27141941/pax-overrides-extension-header.tar.zip) (zipped for size) demonstrates the desynchronization: with `tar tvf`: ``` % tar tvf tests/archives/pax-overrides-extension-header.tar ---------- 0 0 0 2048 Dec 31 1969 longname.txt ---------- 0 0 0 0 Dec 31 1969 file_b ``` with `tar-rs`: ``` ---- pax_size_does_not_apply_to_extension_headers stdout ---- thread 'pax_size_does_not_apply_to_extension_headers' (250476889) panicked at tests/all.rs:2121:27: called `Result::unwrap()` on an `Err` value: Custom { kind: Other, error: "numeric field was not a number: AAAAAAAA when getting cksum for AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" } note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace ``` In the above case, the PoC is not weaponized, so it jumps into the middle of an entry and subsequently fails the checksum test rather than silently continuing with

Properties

ghsa_id
GHSA-3pv8-6f4r-ffg2
severity
medium
summary
tar has a PAX header desynchronization issue
cve_id
GHSA-3pv8-6f4r-ffg2
is_ghsa_only
true
ghsa_published
2026-05-29T19:16:12Z
source_url
https://github.com/advisories/GHSA-3pv8-6f4r-ffg2
ghsa_updated
2026-05-29T19:16:13Z

Related Entities (5)

HAS_WEAKNESS (2)

[Weakness]Improper Input Validation
[Weakness]Access of Resource Using Incompatible Type ('Type Confusion')

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]rust/tar

AFFECTS (1)

[Software]rust/tar

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-3pv8-6f4r-ffg2 — Ninja Signal Threat Intelligence | Ninja Signal