CVE-2025-58183

Published Oct 29, 2025

Last updated 5 months ago

Overview

Description
tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.
Source
security@golang.org
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
4.3
Impact score
1.4
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Severity
MEDIUM

Social media

Hype score
Not currently trending
  1. ๐ŸŸ  HIGH (CVSS 7.5) โ€” CVE-2025-58183 Published: 2025-10-29 golang: archive/tar: Unbounded allocation when parsing GNU sparse map ๐Ÿงฌ CVSS 3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H ๐Ÿ”— NVD: https://t.co/NfvgINyGfR ๐Ÿ“š References: โ€ข https://t.co/WErtKt

    @CVE2026COIN

    22 Jun 2026

    5 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. BREAKING: Fedora ships Incus 6.23 security update for Fedora 42 and 43, fixing CVE-2025-58183, CVE-2026-23954, CVE-2025-69725 and CVE-2026-23953 in the container hypervisor. https://t.co/XYHLgVFmnj

    @threatcluster

    20 Apr 2026

    138 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Grafana is affected by a high-severity security vulnerability, CVE-2025-58183. Update to version 0:9.2.10-24.el9_4 or later to address this issue. https://t.co/BMM6bqWfkZ

    @pulsepatchio

    23 Dec 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. #Fedora 43 Security Advisory: checkpointctl v1.4.1 patches a high-severity DoS flaw (CVE-2025-58183). The tool's sparse map parser could be forced into unbounded memory allocation. Read more: ๐Ÿ‘‰ https://t.co/9xQQMqKm5k #Security https://t.co/z8dffyRnz8

    @Cezar_H_Linux

    19 Dec 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. URGENT: #Fedora docker-buildkit security patches available for CVE-2025-58183, CVE-2025-58185, CVE-2025-58188, CVE-2025-58189, CVE-2025-61723 Read more: ๐Ÿ‘‰ https://t.co/1s46wqrgPS #Security https://t.co/WcSSlZybiB

    @Cezar_H_Linux

    27 Nov 2025

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-58183 tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large nuโ€ฆ https://t.co/ijNCL5puFz

    @CVEnew

    29 Oct 2025

    290 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes