Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header
Published May 26, 2026
7.5
HIGHCVSS 3.1
EPSS 0.45%
Description
Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.
_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.
A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.
Affected products
-
- Version 0StatusaffectedConstraints<3.10
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Bingos | Archive::Tar | unaffected |
|
No data.
Red Hat Enterprise Linux 10
perl-Archive-Tar-0:3.02-512.el10_2.2
Fixed · RHSA-2026:49523
Red Hat Enterprise Linux 8
perl-Archive-Tar-0:2.30-3.el8_10
Fixed · RHSA-2026:49524
Red Hat Enterprise Linux 8
perl:5.32-8100020260723094404.651ee29f
Fixed · RHSA-2026:48225
Red Hat Enterprise Linux 9
perl-Archive-Tar-0:2.38-6.el9_8.2
Fixed · RHSA-2026:49525
Red Hat Enterprise Linux 7
perl-Archive-Tar
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | perl-Archive-Tar-0:3.02-512.el10_2.2 | Fixed | RHSA-2026:49523 |
| Red Hat Enterprise Linux 8 | perl-Archive-Tar-0:2.30-3.el8_10 | Fixed | RHSA-2026:49524 |
| Red Hat Enterprise Linux 8 | perl:5.32-8100020260723094404.651ee29f | Fixed | RHSA-2026:48225 |
| Red Hat Enterprise Linux 9 | perl-Archive-Tar-0:2.38-6.el9_8.2 | Fixed | RHSA-2026:49525 |
| Red Hat Enterprise Linux 7 | perl-Archive-Tar | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to Archive::Tar 3.10 or later.
Red Hat statement
This Important flaw in perl-Archive-Tar allows a Denial of Service via memory exhaustion when processing specially crafted tar archives. The Archive::Tar module's _read_tar() method reads entry payload sizes from the tar header without enforcing an upper bound, allowing an attacker to craft a tar archive whose header declares a multi-gigabyte entry size, causing immediate large memory allocation. Applications or scripts that process untrusted tar files using Archive::Tar are vulnerable to resource exhaustion.
Red Hat mitigation
To mitigate this issue, avoid processing untrusted tar archives with applications using Perl's Archive::Tar module. If untrusted tar processing is required, consider imposing resource limits (e.g., ulimit) on the processes handling tar files to contain memory exhaustion and prevent wider system impact.
References (8)
- http://www.openwall.com/lists/oss-security/2026/05/26/4 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-9538 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2481315 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31775 Advisory
- https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch patch
- https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes release-notesRelease Notes
- https://nvd.nist.gov/vuln/detail/CVE-2026-9538
- https://www.cve.org/CVERecord?id=CVE-2026-9538
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/05/26/4 | Mailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2026-9538 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2481315 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31775 | Advisory | |
| https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch | patch | |
| https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes | release-notesRelease Notes | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-9538 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-9538 |
Change history (0)
No recorded changes yet.