{"id":"GHSA-3cv2-h65g-fgmm","summary":"astral-tokio-tar has a PAX Header Desynchronization issue","details":"### Impact\n\nVersions of astral-tokio-tar prior to 0.6.2 contain a PAX header interpretation bug that allows manipulated entries to be made selectively visible or invisible during extraction with astral-tokio-tar versus other tar implementations. An attacker could use this differential to smuggle unexpected files onto a victim's filesystem.\n\n### Details\n\nWhen a tar stream contains multiple \"header\" entries prior to a file entry, astral-tokio-tar applies the PAX header (`x`) to the next entry in the stream, regardless of type. For example, a stream of `x -\u003e L -\u003e file` (PAX, GNU longname, file) would result in `x`'s extensions being applied to `L` rather than to `file`.\n\n[Per POSIX pax](https://pubs.opengroup.org/onlinepubs/9799919799/utilities/pax.html), this is incorrect: a PAX header always applies to a file entry, not any intermediary entries. See the \"pax Header Block\" section for the specific prescription there.\n\nAs a result of this, an attacker can contrive a tar containing a sequence of tar headers such that astral-tokio-tar applies the PAX header's size extension to the next header in sequence, effectively desynchronizing the stream and enabling astral-tokio-tar specific skippage/extraction of members. In other words, a file can be contrived to extract differently on astral-tokio-tar than on other tar parsers.\n\n### Patches\n\nVersions 0.6.2 and newer of astral-tokio-tar address this differential.\n\n### Workarounds\n\nUsers are advised to upgrade to version 0.6.1 or newer to address this advisory.\n\nThere is no workaround other than upgrading. Users should experience no breaking changes as a result of the upgrade.\n\n### Resources\n\n- GHSA-j5gw-2vrg-8fgx is a similar PAX desynchronization bug\n- GHSA-fp55-jw48-c537 is another similar PAX desynchronization bug","aliases":["RUSTSEC-2026-0145"],"modified":"2026-05-29T19:15:14.574456772Z","published":"2026-05-29T19:08:23Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-29T19:08:23Z","severity":"MODERATE","cwe_ids":["CWE-20","CWE-843"],"nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/astral-sh/tokio-tar/security/advisories/GHSA-3cv2-h65g-fgmm"},{"type":"PACKAGE","url":"https://github.com/astral-sh/tokio-tar"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0145.html"}],"affected":[{"package":{"name":"astral-tokio-tar","ecosystem":"crates.io","purl":"pkg:cargo/astral-tokio-tar"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.6.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-3cv2-h65g-fgmm/GHSA-3cv2-h65g-fgmm.json","last_known_affected_version_range":"\u003c= 0.6.1"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}