[CVE-2025-13462]: tarfile: Skip DIRTYPE normalization during GNU long name and link handling
March 12, 2026
6:02 p.m.
There is a LOW severity vulnerability affecting CPython.
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.
Please see the linked CVE ID for the latest information on affected versions:
67
Age (days ago)
67
Last active (days ago)
0 comments
1 participants
participants (1)
-
Seth Larson