Back

MEDIUM

tar: Infinite read loop in sparse_dump_region function in sparse.c

Published Dec 26, 2018

Description

GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file that is supposed to be archived by a different user's process (e.g., a system backup running as root).

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 8 is not affected by this vulnerability because ships already patched version of tar.

Metrics

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 26, 2018
Updated Aug 5, 2024
Reserved Dec 26, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 26, 2018