CVE-2026-6103EPSS p5.4%
CVE-2026-6103CVE-2026-6103
Description
phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF silently wraps. The parser then skips the wrong number of data blocks and interprets attacker-controlled file content as the next TAR header, which lets a crafted archive inject entries that PharData reports and extracts as if they were genuine.
Scoring
| CVSS | 4.3 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
| EPSS | 0.17% probability of exploitation · percentile 5.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-29 |