{"id":"BIT-php-min-2026-6103","summary":"Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection","details":"phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF silently wraps. The parser then skips the wrong number of data blocks and interprets attacker-controlled file content as the next TAR header, which lets a crafted archive inject entries that PharData reports and extracts as if they were genuine.","aliases":["BIT-libphp-2026-6103","BIT-php-2026-6103","CVE-2026-6103"],"modified":"2026-10-01T10:11:17.213182123Z","published":"2026-10-01T09:34:03.080Z","database_specific":{"severity":"Medium","cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"]},"references":[{"type":"WEB","url":"https://github.com/php/php-src/security/advisories/GHSA-j3wh-g957-2m85"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6103"}],"affected":[{"package":{"name":"php-min","ecosystem":"Bitnami","purl":"pkg:bitnami/php-min"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.2.0"},{"fixed":"8.2.34"},{"introduced":"8.3.0"},{"fixed":"8.3.35"},{"introduced":"8.4.0"},{"fixed":"8.4.26"},{"introduced":"8.5.0"},{"fixed":"8.5.11"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/php-min/BIT-php-min-2026-6103.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"}]}],"schema_version":"1.9.0"}