PAX Header Desynchronization - Vulnerability

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 3, 2025
Last Seen
November 3, 2025

PAX Header Desynchronization refers to a vulnerability class where improper handling of TAR PAX extended headers can desynchronize archive parsing, potentially enabling crafted archives to bypass checks or cause unsafe extraction.

Overview

PAX Header Desynchronization refers to a vulnerability class where improper handling of TAR PAX extended headers can desynchronize archive parsing, potentially enabling crafted archives to bypass checks or cause unsafe extraction. Its significance stems from TAR/PAX's ubiquity in packaging and backups, meaning exploitable desynchronization could impact a wide range of tooling and workflows. Note: The provided articles do not describe this entity directly; they instead report Fedora 42 CVEs affecting other components.

Related Threat Clusters

  • Fedora 42 and 43 uv Package Installer Security Advisory

    Fedora has issued a security advisory for the uv package installer, a fast Python package installer written in Rust. The advisory addresses vulnerabilities affecting versions 0.9.5 and 43, which could impact users…

    2 articles · Updated November 5, 2025
  • Critical Vulnerabilities in Rust Reqsign Affect Multiple Services

    Multiple critical vulnerabilities have been identified in the Rust reqsign library, affecting services such as AWS, Azure, and Google. Key issues include a denial-of-service threat and a critical CVE-2025-62518 related…

    8 articles · Updated November 15, 2025
  • Fedora 42 Security Fix for CVE-2025-62518 in Rust Libraries

    Fedora 42 has released a security update addressing CVE-2025-62518, which affects the reqsign and rust-tikv-jemallocator libraries. The vulnerability involves a parser desynchronization issue when reading tar archives…

    2 articles · Updated November 3, 2025
  • Fedora uv Package Installer Security Updates 2025

    Multiple security advisories were issued for the Fedora uv Python package installer, which is a fast alternative to pip. The updates address important security vulnerabilities, including CVE-2025, affecting users of…

    4 articles · Updated November 15, 2025

Recent Intelligence Reports

  • Fedora 42: uv 0.9.5 Important Security Fix CVE-2025 — Linuxsecurity · November 3, 2025
  • Fedora 42: Critical CVE-2025-62518 in rust-reqsign-http-send — Linuxsecurity · November 3, 2025
  • Fedora 42: rust-tikv-jemallocator Critical CVE-2025 — Linuxsecurity · November 3, 2025

CVSS v3.1 Breakdown