tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 08 Apr 2026 01:45:00 +0000

Type Values Removed Values Added
Description tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.
Title Unbounded allocation for old GNU sparse in archive/tar
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-04-08T01:06:57.416Z

Reserved: 2026-03-11T16:38:46.557Z

Link: CVE-2026-32288

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-08T02:16:03.707

Modified: 2026-04-08T02:16:03.707

Link: CVE-2026-32288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.