Microsoft Security Response Center guidance
CBL-Mariner Releases
Vendor-listed releases
- 1.22.3-17
- 1.57.0-17
- 1.14.2-13
- 2.62.0-10
- 25.0.3-14
- 1.14.4-7
- 1.55.0-26
- 24.0.9-19
Vulnerability intelligence
CVE-2025-58183 and is rated Medium severity with a CVSS score of 4.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CBL-Mariner Releases
tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations.