VDB
Sign up
HIGH8.1

RUSTSEC-2025-0110

astral-tokio-tar Vulnerable to PAX Header Desynchronization

Details

Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers.

This vulnerability was disclosed to multiple Rust tar parsers, all derived from the original async-tar fork of tar-rs.

For additional information see [Edera's blog post](https://edera.dev/stories/tarmageddon).

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/astral-tokio-tar
Introduced in: 0.0.0-0Fixed in: 0.5.6

Upgrade astral-tokio-tar to 0.5.6 or newer (ecosystem crates.io).

References