Back

HIGH

Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header

Published May 26, 2026

Description

Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.

_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.

A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.

Affected products

Remediation

Vendor solution

Upgrade to Archive::Tar 3.10 or later.

Red Hat statement

This Important flaw in perl-Archive-Tar allows a Denial of Service via memory exhaustion when processing specially crafted tar archives. The Archive::Tar module's _read_tar() method reads entry payload sizes from the tar header without enforcing an upper bound, allowing an attacker to craft a tar archive whose header declares a multi-gigabyte entry size, causing immediate large memory allocation. Applications or scripts that process untrusted tar files using Archive::Tar are vulnerable to resource exhaustion.

Red Hat mitigation

To mitigate this issue, avoid processing untrusted tar archives with applications using Perl's Archive::Tar module. If untrusted tar processing is required, consider imposing resource limits (e.g., ulimit) on the processes handling tar files to contain memory exhaustion and prevent wider system impact.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published May 26, 2026
Updated May 28, 2026
Reserved May 25, 2026
CISA Vulnrichment
Updated May 28, 2026
NVD
Status Modified
Modified Jul 23, 2026
Red Hat
Severity Important
Public date May 26, 2026
ENISA EUVD
Assigner CPANSec
Published May 26, 2026
Updated May 28, 2026
Exploited since n/a
EUVD-2026-31775