CVE-2023-39804: GNU Tar

Medium severity, CVSS 6.2. EPSS: 0.3% chance of exploitation in the next 30 days.

In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.

Affected products

  • GNU Tar: before 1.35 (fixed in 1.35)

Published 2024-03-27. Last modified 2026-06-17.