CVE-2026-9538Disclosure(archive\ / \)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value. A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-789

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • \

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
\

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-26: 2Technical Details · 2026-05-26: 105-26
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets4 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN Archive::Tar CVE-2026-42496: Extract symlinks with attacker controlled targets outside the extraction directory https://www.openwall.com/lists/oss-security/2026/05/26/2 CVE-2026-42497: ditto for hardlinks https://www.openwall.com/lists/oss-security/2026/05/26/3 CVE-2026-9538: Memory exhaustion via tar header https://www.openwall.com/lists/oss-security/2026/05/26/4

    Post summary

    Three CVEs in Perl CPAN Archive::Tar were disclosed, describing symlink/hardlink extraction outside the target directory and memory exhaustion via tar header; advisory links are provided but no PoC, exploit, or patches are mentioned.

    01051643
    4.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-9538 CVE-2026-9538 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9538

    Post summary

    The content simply lists CVE‑2026‑9538 with a link, but provides no substantive technical or contextual information.

    0000088
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apparchive\\tar_project--

Explore more