RUSTSEC-2025-0110
astral-tokio-tar Vulnerable to PAX Header Desynchronization
Details
Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers.
This vulnerability was disclosed to multiple Rust tar parsers, all derived from the original async-tar fork of tar-rs.
For additional information see [Edera's blog post](https://edera.dev/stories/tarmageddon).
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0Fixed in: 0.5.6Upgrade astral-tokio-tar to 0.5.6 or newer (ecosystem crates.io).