{"id":146043,"date":"2025-10-21T23:12:42","date_gmt":"2025-10-21T21:12:43","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-rust-bibliotekah-dlya-formata-tar-privodyashhaya-k-raspakovke-fajlov-iz-vlozhennogo-arhiva"},"modified":"2025-10-21T23:12:42","modified_gmt":"2025-10-21T21:12:43","slug":"uyazvimost-v-rust-bibliotekah-dlya-formata-tar-privodyashhaya-k-raspakovke-fajlov-iz-vlozhennogo-arhiva","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-rust-bibliotekah-dlya-formata-tar-privodyashhaya-k-raspakovke-fajlov-iz-vlozhennogo-arhiva","title":{"rendered":"Vulnerability in Rust libraries for TAR format that leads to extracting files from a nested archive","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>A vulnerability (CVE-2025-62518, codename TARmageddon) has been identified in the Rust library async-tar, which provides functions for reading and writing tar archives. This vulnerability allows specially crafted tar archives to extract not only files contained within them but also files present in nested tar archives upon extraction. This vulnerability can be exploited to bypass archive verification systems and extract files that were not subject to checks.    <\/p>\n<p>The vulnerability also appears in forks of the async-tar library, such as tokio-tar, krata-tokio-tar, and astral-tokio-tar, as well as in utilities based on them, such as the uv package manager, developed as a high-performance alternative to 'pip' for Python projects. Notable projects that use vulnerable libraries include the testcontainers toolkit for running docker containers and the WebAssembly runtime wasmCloud. In the crates.io repository, the async-tar library has seen 1.3 million downloads in the last 90 days, tokio-tar has 2.2 million, and testcontainers has 2.9 million.    <\/p>\n<p>The vulnerability is caused by an incorrect choice of position when parsing different size values in ustar and PAX headers. In tar archives in PAX format, two headers are specified for each file inside the archive\u2014the classic ustar and the extended PAX. The issue arises because the vulnerable libraries, when unpacking files, used the size from the outdated ustar header instead of calculating the offset based on the size from the extended PAX header. With a zero size value in the ustar header, the content following it was processed as a valid TAR header block for the next file.   <center><img decoding=\"async\" alt=\"Vulnerability in Rust libraries for TAR format that leads to extracting files from a nested archive\" src=\"\/wp-content\/uploads\/2025\/10\/7de5eeee8420b77faa0bca075f275700.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>    <center><img decoding=\"async\" alt=\"Vulnerability in Rust libraries for TAR format that leads to extracting files from a nested archive\" src=\"\/wp-content\/uploads\/2025\/10\/538645342d5a4408b327ffd87c659c4f.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>  <\/p>\n<p>To exploit the vulnerability, it is sufficient to create a TAR archive where the ustar header specifies a zero size, and the PAX header contains the actual size, causing the contents of the file with another tar archive to be processed as part of the main archive. Example code for creating such archives is available on GitHub. The vulnerability has been patched in releases of tokio-tar 0.5.6 and uv 0.9.5. Fixes for other libraries have not yet been published, but patches have been prepared separately for astral-tokio-tar, async-tar, and krata-tokio-tar.                  <\/p>\n<p>Vulnerabilities in the libraries have been assigned a danger level of 8.1 out of 10, as the issue can be exploited to overwrite unpacked files (vulnerable implementations will unpack files different from those visible in the archive). Meanwhile, the vulnerability in the uv package manager is marked as non-threatening, as if an attacker can influence the contents of the original archive, there is no point in complicating the attack and exploiting the vulnerability through a nested archive when code execution can be achieved through build scripts in the main archive.      <\/p>\n<p>The researchers who discovered the vulnerability proposed several hypothetical attack scenarios that allow bypassing security checks and achieving code execution through configuration file replacements or interference in the build process. It is implied that the submitted archive will pass automated checks by the security scanner and manual audits, during which the auditor may not notice the suspicious nested archive containing other files. Consequently, when unpacked using Rust libraries, different content than expected will be extracted from the archive.    <\/p>\n<p>For instance, an attacker could upload a modified archive to the PyPI repository, which would pass verification based on the analysis of the main archive's contents, containing a legitimate pyproject.toml file. When processing this package using the uv utility, the legitimate pyproject.toml will be replaced with a malicious version from the nested archive containing commands that will execute during the building process on the developer's computer or in the continuous integration system. Similarly, files in the container can be overwritten when extracting the container image using the testcontainers toolkit.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=64093\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u043d\u043e\u0439 \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Rust \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 async-tar, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f \u0438 \u0437\u0430\u043f\u0438\u0441\u0438 tar-\u0430\u0440\u0445\u0438\u0432\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-62518, \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f TARmageddon), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0440\u0438 \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e tar-\u0430\u0440\u0445\u0438\u0432\u0430 \u043d\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u0438\u0437\u0432\u043b\u0435\u0447\u044c \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0435 \u0432 \u043d\u0451\u043c \u0444\u0430\u0439\u043b\u044b, \u043d\u043e \u0438 \u0444\u0430\u0439\u043b\u044b, \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0438\u0435\u0441\u044f \u0432\u043e \u0432\u043b\u043e\u0436\u0435\u043d\u043d\u043e\u043c tar-\u0430\u0440\u0445\u0438\u0432\u0435. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0430 \u0434\u043b\u044f \u043e\u0431\u0445\u043e\u0434\u0430 \u0441\u0438\u0441\u0442\u0435\u043c \u0432\u0435\u0440\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0430\u0440\u0445\u0438\u0432\u043e\u0432 \u0438 \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0438 \u0444\u0430\u0439\u043b\u043e\u0432, \u0434\u043b\u044f \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043d\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":146044,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-146043","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u043d\u043e\u0439 \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Rust \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 async-tar, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f \u0438 \u0437\u0430\u043f\u0438\u0441\u0438 tar-\u0430\u0440\u0445\u0438\u0432\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-62518, \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f TARmageddon), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0440\u0438 \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-rust-bibliotekah-dlya-formata-tar-privodyashhaya-k-raspakovke-fajlov-iz-vlozhennogo-arhiva\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Rust-\u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 \u0434\u043b\u044f \u0444\u043e\u0440\u043c\u0430\u0442\u0430 TAR, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0435 \u0444\u0430\u0439\u043b\u043e\u0432 \u0438\u0437 \u0432\u043b\u043e\u0436\u0435\u043d\u043d\u043e\u0433\u043e \u0430\u0440\u0445\u0438\u0432\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u043d\u043e\u0439 \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Rust \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 async-tar, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f \u0438 \u0437\u0430\u043f\u0438\u0441\u0438 tar-\u0430\u0440\u0445\u0438\u0432\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-62518, \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f TARmageddon), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0440\u0438 \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-rust-bibliotekah-dlya-formata-tar-privodyashhaya-k-raspakovke-fajlov-iz-vlozhennogo-arhiva\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-10-21T21:12:43+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-10-21T21:12:43+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerability in Rust libraries for TAR format leading to extraction of files from a nested archive | ProHoster","description":"A vulnerability (CVE-2025-62518, codename TARmageddon) has been identified in the Rust library async-tar, which provides functions for reading and writing tar archives, allowing for exploitation when unpacking specially crafted archives.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-rust-bibliotekah-dlya-formata-tar-privodyashhaya-k-raspakovke-fajlov-iz-vlozhennogo-arhiva","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Rust-\u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 \u0434\u043b\u044f \u0444\u043e\u0440\u043c\u0430\u0442\u0430 TAR, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0435 \u0444\u0430\u0439\u043b\u043e\u0432 \u0438\u0437 \u0432\u043b\u043e\u0436\u0435\u043d\u043d\u043e\u0433\u043e \u0430\u0440\u0445\u0438\u0432\u0430 | ProHoster","og:description":"\u0412 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u043d\u043e\u0439 \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Rust \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 async-tar, \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u044e\u0449\u0435\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f \u0438 \u0437\u0430\u043f\u0438\u0441\u0438 tar-\u0430\u0440\u0445\u0438\u0432\u043e\u0432, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-62518, \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f TARmageddon), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u0440\u0438 \u0440\u0430\u0441\u043f\u0430\u043a\u043e\u0432\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-rust-bibliotekah-dlya-formata-tar-privodyashhaya-k-raspakovke-fajlov-iz-vlozhennogo-arhiva","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-10-21T21:12:43+00:00","article:modified_time":"2025-10-21T21:12:43+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"146043","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 15:29:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 15:29:20","updated":"2026-01-23 15:29:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/146043","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=146043"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/146043\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/146044"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=146043"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=146043"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=146043"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}