CVE-2026-32288 PUBLISHED

Unbounded allocation for old GNU sparse in archive/tar

Assigner: Go
Reserved: 11.03.2026 Published: 08.04.2026 Updated: 08.04.2026

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

Product Status

Vendor Go standard library
Product archive/tar
Versions Default: unaffected
  • affected from 0 to 1.25.9 (excl.)
  • affected from 1.26.0-0 to 1.26.2 (excl.)

Credits

  • Colin Walters (walters@verbum.org)
  • Uuganbayar Lkhamsuren (https://github.com/uug4na)
  • Jakub Ciolek

References

Problem Types

  • CWE-400: Uncontrolled Resource Consumption