TARmageddon flaw in abandoned Rust library enables RCE attacks
ID: 7cff0a39-485f-537f-9950-943aec8f45db
STIX ID: report--7cff0a39-485f-537f-9950-943aec8f45db
Feed Name: Bleeping Computer
A high-severity logic flaw (CVE-2025-62518) dubbed “TARmageddon” in the abandoned async-tar library and its popular fork tokio-tar allows unauthenticated attackers to inject additional TAR entries when processing nested archives with mismatched headers, enabling file overwrite and potential remote code execution. The vulnerability poses a significant supply-chain risk because tokio-tar has widespread use (millions of downloads) and some forks remain unpatched; maintainers and downstream projects are advised to upgrade to patched forks or remove the vulnerable dependency.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
