CVE-2025-13462

Aliases:UBUNTU-CVE-2025-13462DEBIAN-CVE-2025-13462CGA-25f6-5cxg-gxxxCGA-6fxm-pqmf-fc74CGA-8j9f-6737-4cvmCGA-8wrr-g4v2-c23qCGA-gfh9-cpfg-7xm6CGA-gw48-8hh3-chwgCGA-hm76-h233-rhm4CGA-6gc8-cg7g-qhx7CGA-8h76-8f97-627jCGA-wppv-wm75-qv92CGA-wpw5-rq3h-873cCGA-xfgf-hggg-j9mh
Analyzed
Published: 12 Mar 2026, 17:59
Last modified:13 Aug 2026, 00:30

Vulnerability Summary

Overall Risk (default)
low
13/100
CVSS Score
3.3 LOW
v3.1 (nvd)
EPSS Score
0.16% LOW
0% probability +0.12%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Mar 2026, 17:59
Published
Vulnerability first disclosed
13 Aug 2026, 00:30
Last Modified
Vulnerability information updated

Description

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.

CVSS Metrics

  • v4.0LOWScore: 2CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  • v4.0LOWScore: 2CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1LOWScore: 3.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

EPSS Trends

Current EPSS score: 0.16% Percentile: 6%

Techniques & Countermeasures

  • CWE-20Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

  • CWE-74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

    The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

  • CWE-434Unrestricted Upload of File with Dangerous Type

    The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Affected Systems

  • chainguardpython-3.10

    all | < 3.10.21-r6

  • chainguardpython-3.11

    < 3.11.15-r9

  • chainguardpython-3.12

    all | < 3.12.14-r8

  • chainguardpython-3.13

    < 3.13.13-r0

  • chainguardpython-3.14

    < 3.14.4-r0

  • chainguardpython-3.9

    all

  • wolfipython-3.10

    all | < 3.10.21-r6

  • wolfipython-3.11

    < 3.11.15-r9

  • wolfipython-3.12

    all | < 3.12.14-r8

  • wolfipython-3.13

    < 3.13.13-r0

  • wolfipython-3.14

    < 3.14.4-r0

  • debianpython2.7

    all

  • debianpython3.11

    < 3.11.2-6+deb12u8

  • debianpython3.13

    < 3.13.5-2+deb13u1 | < 3.13.14-1

  • debianpython3.14

    < 3.14.3-4

  • debianpython3.9

    < 3.9.2-1+deb11u7

  • ubuntupython2.7

    all

  • ubuntupython3.10

    < 3.10.12-1~22.04.16

  • ubuntupython3.11

    all | all

  • ubuntupython3.12

    < 3.12.3-1ubuntu0.15

  • ubuntupython3.13

    all

  • ubuntupython3.14

    all

  • ubuntupython3.4

    all

  • ubuntupython3.5

    all

  • ubuntupython3.6

    all

  • ubuntupython3.7

    all

  • ubuntupython3.8

    all

  • ubuntupython3.9

    all

  • python software foundationcpython

    < 3.15.0 | < 3.14.4 | < 3.13.13 | < 3.10.21 | ≥ 3.11.0, < 3.11.16 | ≥ 3.12.0, < 3.12.14 | ≥ 3.13.0, < 3.13.13 | ≥ 3.14.0, < 3.14.4 | ≥ 3.15.0a1, < 3.15.0a8

  • pythonpython

    < 3.13.13 | ≥ 3.14.0, < 3.14.4 | 3.15.0:alpha1 | 3.15.0:alpha2 | 3.15.0:alpha3 | 3.15.0:alpha4 | 3.15.0:alpha5 | 3.15.0:alpha6 | 3.15.0:alpha7

References (16)