CVE-2022-48303: Fedoraproject Fedora

Medium severity, CVSS 5.5. EPSS: 1.5% chance of exploitation in the next 30 days.

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

Affected products

  • Fedoraproject Fedora: version 37 only; version 38 only
  • GNU Tar: up to and including 1.34

Published 2023-01-30. Last modified 2026-06-17.