logo

TARmageddon flaw in abandoned Rust library enables RCE attacks

ID: 7cff0a39-485f-537f-9950-943aec8f45db

STIX ID: report--7cff0a39-485f-537f-9950-943aec8f45db

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-10-22

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

A high-severity logic flaw (CVE-2025-62518) dubbed “TARmageddon” in the abandoned async-tar library and its popular fork tokio-tar allows unauthenticated attackers to inject additional TAR entries when processing nested archives with mismatched headers, enabling file overwrite and potential remote code execution. The vulnerability poses a significant supply-chain risk because tokio-tar has widespread use (millions of downloads) and some forks remain unpatched; maintainers and downstream projects are advised to upgrade to patched forks or remove the vulnerable dependency.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.