CVE-2026-55738
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy without guaranteeing null termination of the source.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| rxi | microtar | 0.1.0 | affected |
Weaknesses
- CWE-121: CWE-121 Stack-based Buffer Overflow
- CWE-170: CWE-170 Improper Null Termination
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://github.com/rxi/microtar/blob/master/src/microtar.c#L111
- https://github.com/rxi/microtar
- https://raw.githubusercontent.com/rxi/microtar/master/src/microtar.c
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.