CVE-2025-58183Patch

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-20: 1Patch / Workaround · 2026-04-20: 104-20
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Fedora ships Incus 6.23 security update for Fedora 42 and 43, fixing CVE-2025-58183, CVE-2026-23954, CVE-2025-69725 and CVE-2026-23953 in the container hypervisor. https://threatcluster.io/cluster/fedora-incus-623-security-update-addresses-multiple-vulnerab-faf3dc82

    Post summary

    Fedora has released a security update (Incus 6.23) that addresses multiple CVEs, including CVE-2025-58183 and several others.

    00000300
    160 followersView on X

Explore more