VDB
Sign up
—

RUSTSEC-2025-0111

`tokio-tar` parses PAX extended headers incorrectly, allows file smuggling

Details

The archive reader incorrectly handles PAX extended headers, when the ustar header incorrectly specifies zero size (`size=000000000000`), while a PAX header specifies a non-zero size, `tokio-tar::Archive` is going to read the file content as tar entry header.

This can be used by a tar file to present different content to `tokio-tar` compared to other tar reader implementations.

This bug is also known as `CVE-2025-62518` and `GHSA-j5gw-2vrg-8fgx`, as those crates share a common ancestor codebase.

The `tokio-tar` crate is archived and no longer maintained, we recommend you switch to an alternative crate such as: - [`astral-tokio-tar`](https://crates.io/crates/astral-tokio-tar)

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/tokio-tar
Introduced in: 0.0.0-0

No fixed version published yet for tokio-tar. Pin to a known-safe version or switch to an alternative.

References