Vulnerability record · CVE-2022-48303 · published 30 January 2023
CVE-2022-48303: Gnu tar out-of-bounds read vulnerability
Gnu · Tar
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.
Description
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CRY7VEL4AIG3GLIEVCTOXRZ | Mailing ListThird Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5VQYCO52Z7GAVCLRYUITN7 | Mailing ListThird Party Advisory |
| https://savannah.gnu.org/bugs/?62387 | ExploitVendor Advisory |
| https://savannah.gnu.org/patch/?10307 | PatchVendor Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CRY7VEL4AIG3GLIEVCTOXRZ | Mailing ListThird Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5VQYCO52Z7GAVCLRYUITN7 | Mailing ListThird Party Advisory |
| https://savannah.gnu.org/bugs/?62387 | ExploitVendor Advisory |
| https://savannah.gnu.org/patch/?10307 | PatchVendor Advisory |
Track CVE-2022-48303 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-48303), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.