After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).
CVSS Details
- CVSS 3.1 Base Score: 6.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Huawei Euleros 2_0_sp10 | huawei-euleros-2_0_sp10-upgrade-libtar-help | Mar 20, 2023 | Dec 19, 2022 | |
| Huawei Euleros 2_0_sp11 | huawei-euleros-2_0_sp11-upgrade-libtar-help | Mar 24, 2023 | Dec 19, 2022 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-libtar | Feb 9, 2023 | Dec 19, 2022 | |
| Huawei Euleros 2_0_sp9 | huawei-euleros-2_0_sp9-upgrade-libtar-help | Mar 9, 2023 | Dec 19, 2022 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Dec 19, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub