Executive brief
The async-tar library, used for processing tar archive files in Rust applications, contains a flaw in how it handles specific archive headers. An attacker can create a specially crafted tar file that appears benign to security scanners but extracts malicious files or different content when processed by this library. This could allow an attacker to bypass security filters, such as malware scanners or audit tools, to deliver harmful payloads to a system.
Technical details
A vulnerability exists in async-tar v0.6.0 where the `poll_next_raw` function in `src/archive.rs` incorrectly applies buffered PAX 'size' extensions to intermediary extension headers (such as GNU longname 'L' or PAX 'x'/'g' headers) instead of the subsequent file entry. This causes the stream cursor to advance by an attacker-controlled amount, leading to a desynchronization between async-tar and POSIX-compliant parsers like GNU tar. An attacker can exploit this to perform 'entry smuggling,' where a file that appears as benign data to a scanner is extracted as a different, potentially malicious file by async-tar. The issue is fixed in version 0.6.1 by ensuring PAX extensions are only applied to standard file entries.
Affected products
- dignifiedquire async-tar 0.6.0
Timeline
- 2026-06-01: advisory: Initial GitHub Advisory published
- 2026-07-08: patched: Version 0.6.1 released with fix