CVE-2019-9923: GNU Tar

High severity, CVSS 7.5. EPSS: 3% chance of exploitation in the next 30 days.

pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.

Affected products

  • GNU Tar: before 1.32 (fixed in 1.32)
  • Opensuse Leap: version 15.0 only

Published 2019-03-22. Last modified 2026-06-17.