{"id":"GHSA-3pv8-6f4r-ffg2","summary":"tar has a PAX header desynchronization issue","details":"### Summary\n\nWhen a tar stream contains multiple \"header\" entries prior to a file entry, tar-rs applies the PAX header (`x`) to the _next_ entry in the stream, regardless of type. For example, a stream of `x -\u003e L -\u003e file` (PAX, GNU longname, file) would result in `x`'s extensions being applied to `L` rather than to `file`.\n\n[Per POSIX pax](https://pubs.opengroup.org/onlinepubs/9799919799/utilities/pax.html), this is incorrect: a PAX header always applies to a file entry, not any intermediary entries. See the \"pax Header Block\" section for the specific prescription there.\n\nAs a result of this, an attacker can contrive a tar containing a sequence of tar headers such that tar-rs applies the PAX header's `size` extension to the next header in sequence, effectively desynchronizing the stream and enabling tar-rs specific skippage/extraction of members. In other words, a file can be contrived to extract differently on tar-rs than on other tar parsers.\n\n### PoC\n\n[This tar](https://github.com/user-attachments/files/27141941/pax-overrides-extension-header.tar.zip) (zipped for size) demonstrates the desynchronization: with `tar tvf`:\n\n```\n% tar tvf tests/archives/pax-overrides-extension-header.tar \n----------  0 0      0        2048 Dec 31  1969 longname.txt\n----------  0 0      0           0 Dec 31  1969 file_b\n```\n\nwith `tar-rs`:\n\n```\n---- pax_size_does_not_apply_to_extension_headers stdout ----\n\nthread 'pax_size_does_not_apply_to_extension_headers' (250476889) panicked at tests/all.rs:2121:27:\ncalled `Result::unwrap()` on an `Err` value: Custom { kind: Other, error: \"numeric field was not a number: AAAAAAAA when getting cksum for AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\" }\nnote: run with `RUST_BACKTRACE=1` environment variable to display a backtrace\n```\n\nIn the above case, the PoC is not weaponized, so it jumps into the middle of an entry and subsequently fails the checksum test rather than silently continuing with attacker-controlled archive state.\n\n### Impact\n\nThis is very similar to GHSA-j5gw-2vrg-8fgx and GHSA-fp55-jw48-c537 in impact -- an attacker can use this to extract (or not extract) files from a tar stream depending on the tar parser used, which in turn can be used to obscure the presence of malicious files.","modified":"2026-06-01T10:59:10.816473215Z","published":"2026-05-29T19:16:12Z","related":["CGA-8ww7-68g5-5224"],"database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-20","CWE-843"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-05-29T19:16:12Z"},"references":[{"type":"WEB","url":"https://github.com/composefs/tar-rs/security/advisories/GHSA-3pv8-6f4r-ffg2"},{"type":"WEB","url":"https://github.com/composefs/tar-rs/pull/454"},{"type":"WEB","url":"https://github.com/composefs/tar-rs/commit/bab14dd84b411ac16ecb56d4f2d2f7bfb88a9838"},{"type":"PACKAGE","url":"https://github.com/composefs/tar-rs"},{"type":"WEB","url":"https://github.com/composefs/tar-rs/releases/tag/0.4.46"}],"affected":[{"package":{"name":"tar","ecosystem":"crates.io","purl":"pkg:cargo/tar"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.4.46"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-3pv8-6f4r-ffg2/GHSA-3pv8-6f4r-ffg2.json","last_known_affected_version_range":"\u003c= 0.4.45"}}],"schema_version":"1.7.5"}