After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).
CVSS Details
- CVSS 3.1 Base Score: 6.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Huawei Euleros 2_0_sp10 | — | Upgrade libtar-help | Mar 20, 2023 | Dec 19, 2022 |
| Huawei Euleros 2_0_sp11 | — | Upgrade libtar-help | Mar 24, 2023 | Dec 19, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade libtar | Feb 9, 2023 | Dec 19, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade libtar-help | Mar 9, 2023 | Dec 19, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 19, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub