Skip to content

RUSTSEC-2026-0112: PAX Header Desynchronization in astral-tokio-tar #333

@xtqqczze

Description

@xtqqczze

PAX Header Desynchronization in astral-tokio-tar

Details
Package astral-tokio-tar
Version 0.6.0
URL GHSA-fp55-jw48-c537
Date 2026-04-27
Patched versions >=0.6.1

Versions of astral-tokio-tar prior to 0.6.1 contain a PAX header interpretation
bug that allows manipulated entries to be made selectively visible or invisible
during extraction with astral-tokio-tar versus other tar implementations.
An attacker could use this differential to smuggle unexpected files onto a
victim's filesystem.

See advisory page for additional details.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions