CVE-2026-32288

Published: April 9, 2026Last modified: April 11, 2026

Description

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

Severity score breakdown

ParameterValue
Base score5.5
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgoFixed (1.25.9-r0)
25 LTSgoFixed (1.25.9-r0)
StreamgoFixed (1.26.2-r0)
Hardened Containers23 LTSgoFixed (1.25.9-r0)
25 LTSgoFixed (1.25.9-r0)
StreamgoFixed (1.26.2-r0)

References

ON THIS PAGE