CVE-2025-8194: Tarfile infinite loop during parsing with negative member offset
There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives.
This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1
Security readout for executives and security teams
Plain-English summary
CPython’s tarfile module can become stuck indefinitely when parsing a malicious tar archive containing negative member offsets. Affected services may stop responding or exhaust worker capacity, causing denial of service. The supplied evidence does not indicate data theft, code execution, or data modification.
Executive priority
Prioritize internet-facing upload services and business-critical archive pipelines. Remediate promptly where untrusted tar files are processed because one malicious archive could stall workers and disrupt availability. Lower priority applies where tarfile is absent or all archive inputs are trusted and tightly controlled.
Technical view
TarFile extraction and entry-enumeration APIs accept negative member offsets without raising an error. Parsing can then enter an infinite loop and deadlock, producing an availability failure classified as CWE-835. Remote impact depends on an application accepting and processing attacker-controlled tar archives.
Likely exposure
Highest exposure exists in Python services, automation, upload handlers, and archive-processing pipelines that use tarfile with untrusted archives. The bundle lists CPython version starting points from 3.10.0 through 3.14.0a1, but does not clearly specify complete affected or fixed ranges.
Exploitation context
The CVSS 3.1 score is 7.5 with network reachability, low complexity, no privileges, and no user interaction. However, remote exploitation requires an exposed application path that parses attacker-supplied tar data. The bundle reports no KEV listing and provides no evidence of active exploitation.
Researcher notes
This is an availability-only parsing flaw based on the supplied CVSS vector and description; no confidentiality or integrity impact is established. Assess transitive tarfile use, worker concurrency, timeout behavior, and recovery controls. Exact affected and fixed release boundaries are insufficiently represented in the bundle and should be confirmed with vendor guidance.
Mitigation direction
Review the Python security announcement and determine the vendor-supported fixed release for each deployed branch.
Upgrade affected Python runtimes according to confirmed vendor guidance and distribution-specific advisories.
If immediate upgrades are impossible, evaluate the linked vendor-provided mitigation patch.
Restrict or suspend processing of untrusted tar archives until remediation is verified.
Apply resource limits and isolation around archive-processing workers to reduce denial-of-service impact.
Validation and detection
Inventory Python runtime versions and applications importing or indirectly using tarfile.
Trace whether external users, partners, or automated feeds can supply tar archives.
Confirm deployed code includes the upstream negative-offset validation or documented mitigation.
Use a controlled, non-production regression test to verify malformed archives terminate safely.
Monitor archive-processing workers for hangs, timeouts, queue growth, and abnormal resource consumption.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-835: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-835 · source CWE mapping
Loop with Unreachable Exit Condition ('Infinite Loop')
Loop with Unreachable Exit Condition ('Infinite Loop') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.