CVE-2024-6232: Regular-expression DoS when parsing TarFile headers

Published Sep 3, 2024
·
Updated

Last updated 7 May 2025

Other sources

Python CPython is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) flaw when parsing TarFile headers. By using specially crafted tar archives, a remote attacker could exploit this vulnerability to cause a denial of service.

Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

IBM

There is a MEDIUM severity vulnerability affecting CPython.

Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

MITRE

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile. TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

F5

Affected Software

24 affected componentsFixes available
IBM Concert Software<=1.0.0, 1.0.1, 1.0.2, 1.0.2.1, 1.0.3
Python Python<3.8.20
Python Python>=3.9.0<3.9.20
Python Python>=3.10.0<3.10.15
Python Python>=3.11.0<3.11.10
Python Python>=3.12.0<3.12.6
Python Python=3.13.0-alpha0
Python Python=3.13.0-alpha1
Python Python=3.13.0-alpha2
Python Python=3.13.0-alpha3
Python Python=3.13.0-alpha4
Python Python=3.13.0-alpha5
Python Python=3.13.0-alpha6
Python Python=3.13.0-beta1
Python Python=3.13.0-beta2
Python Python=3.13.0-beta3
Python Python=3.13.0-beta4
Python Python=3.13.0-rc1
debian/python2.7<=2.7.18-8+deb11u1
debian/python3.11<=3.11.2-6+deb12u3
3.11.2-6+deb12u5
debian/python3.12
3.12.10-1
debian/python3.13
3.13.3-2
debian/python3.9<=3.9.2-1
3.9.2-1+deb11u3
F5 BIG-IQ Centralized Management>=8.2.0<=8.4.0
8.4.1

Event History

Sep 3, 2024
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·01:20 PM
DescriptionSeverityAffected Software
Oct 25, 2024
Advisory Published
via F5·06:13 PM
Data Sourced
via F5·06:13 PM
DescriptionSeverityWeaknessAffected Software
May 11, 2025
Data Sourced
via Ubuntu·06:34 AM
RemedyDescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-6232?

CVE-2024-6232 has a moderate severity rating due to its potential for causing a denial of service.

2

How do I fix CVE-2024-6232?

To fix CVE-2024-6232, update affected Python versions to the latest patched releases listed in the vulnerability advisories.

3

Which software is affected by CVE-2024-6232?

CVE-2024-6232 affects several versions of Python and products from IBM and F5 listed in the vulnerability description.

4

How does CVE-2024-6232 impact Python users?

CVE-2024-6232 can lead to denial of service for applications that utilize vulnerable Python libraries to handle tar archives.

5

What type of attack does CVE-2024-6232 enable?

CVE-2024-6232 enables a regular expression denial of service (ReDoS) attack through specially crafted tar files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203