Description
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4033-1 | libtar security update |
EUVD |
EUVD-2021-20321 | An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read. |
Ubuntu USN |
USN-7398-1 | libtar vulnerabilities |
References
History
Mon, 03 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 02 Apr 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openatom
Openatom openeuler |
|
| CPEs | cpe:2.3:o:huawei:openeuler:20.03:sp3:*:*:lts:*:*:* cpe:2.3:o:huawei:openeuler:22.03:*:*:*:lts:*:*:* |
cpe:2.3:o:openatom:openeuler:20.03:sp1:*:*:lts:*:*:* cpe:2.3:o:openatom:openeuler:20.03:sp3:*:*:lts:*:*:* cpe:2.3:o:openatom:openeuler:22.03:*:*:*:lts:*:*:* |
| Vendors & Products |
Huawei
Huawei openeuler |
Openatom
Openatom openeuler |
Status: PUBLISHED
Assigner: openEuler
Published:
Updated: 2025-11-03T20:33:37.233Z
Reserved: 2021-05-28T00:00:00.000Z
Link: CVE-2021-33644
No data.
Status : Modified
Published: 2022-08-10T20:15:20.517
Modified: 2025-11-03T21:15:41.270
Link: CVE-2021-33644
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN