← Back to search

CVE-2026-71267

9.8 CRITICALpublic exploit available

Published 2026-08-05 · Updated 2026-08-10

AI risk analysis

Summary
The flaw in microtar allows an attacker to overwrite the 100-byte field of a stack-allocated structure via a long entry name, leading to potential buffer overflow and execution of arbitrary code.
Exploitability
Exploitation is relatively straightforward given the lack of input validation, and requires an attacker to supply a long entry name.
Blast radius
If exploited, this flaw could lead to full system compromise, as it allows for arbitrary code execution.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest version of microtar, or apply the specific patch provided by the vendor.
rcebuffer-overflowstack-overflowarbitrary-code-execution

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-121

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.