CRITICAL
libtar: out-of-bounds read in gnu_longlink
Published Aug 9, 2022
9.1
CRITICALCVSS 3.1
EPSS 1.77%
Description
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.
Affected products
- Vendor n/a Product Libtar Defaultunknown
Affected
- < 1.2.21
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Libtar | unknown | Affected
|
Configuration 2
Configuration 3
OR
- 35
- 36
- 37
No data.
Red Hat Enterprise Linux 8
libtar-0:1.2.20-17.el8
Fixed · RHSA-2023:2898
Red Hat Enterprise Linux 6
libtar
Out of support scope
Red Hat Enterprise Linux 7
libtar
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | libtar-0:1.2.20-17.el8 | Fixed | RHSA-2023:2898 |
| Red Hat Enterprise Linux 6 | libtar | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libtar | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (12)
- https://access.redhat.com/security/cve/CVE-2021-33643 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2121289 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-20320 Advisory
- https://lists.debian.org/debian-lts-announce/2025/01/msg00026.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5YSHZY753R7XW6CIKJVAWI373WW3YRRJ/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7Q26QDNOJDOFYWMJWEIK5XR62M2FF6IJ/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WX5YE66CT7Y5C2HTHXSFDKQWYWYWJ2T/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OD4HEBSTI22FNYKOKK7W3X6ZQE6FV3XC/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-33643
- https://www.cve.org/CVERecord?id=CVE-2021-33643
- https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1807 Broken LinkThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner openEuler
Published Aug 9, 2022
Updated Jun 23, 2026
Reserved May 28, 2021
Link CVE-2021-33643
CISA Vulnrichment
Updated Jun 23, 2026
GitHub
No data