UBUNTU-CVE-2025-64118
Dashboard / Vulnerabilities / UBUNTU-CVE-2025-64118
Summary:
Details: node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2.
References: https://ubuntu.com/security/CVE-2025-64118, https://www.cve.org/CVERecord?id=CVE-2025-64118, https://github.com/isaacs/node-tar/security/advisories/GHSA-29xp-372q-xqph, https://github.com/isaacs/node-tar/pull/446, https://github.com/isaacs/node-tar/commit/5330eb04bc43014f216e5c271b40d5c00d45224d, https://github.com/isaacs/node-tar/issues/445
Affected packages
Package
Name: node-tar
Purl: pkg:deb/ubuntu/node-tar?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
