F5-K000159077: Null Pointer Dereference
Published Jan 16, 2026
·Updated
paxdecodeheader in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.
Affected Software
2 affected components
F5 F5OS-A>=1.8.0<=1.8.3, >=1.5.1<=1.5.4
F5 F5OS-C>=1.8.0<=1.8.2, >=1.6.0<=1.6.4
Event History
Jan 16, 2026
Advisory Published
via F5·06:41 PM
Data Sourced
via F5·06:41 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of F5-K000159077?
F5-K000159077 has a medium severity due to a NULL pointer dereference vulnerability.
2
How do I fix F5-K000159077?
To fix F5-K000159077, you should upgrade to the latest version of F5OS-A or F5OS-C that is not affected by this vulnerability.
3
Which versions are affected by F5-K000159077?
F5-K000159077 affects F5OS-A versions 1.5.1 to 1.5.4 and 1.8.0 to 1.8.3, as well as F5OS-C versions 1.6.0 to 1.6.4 and 1.8.0 to 1.8.2.
4
What does F5-K000159077 vulnerability affect?
F5-K000159077 affects the pax_decode_header function in sparse.c in GNU Tar prior to 1.32.
5
What can be exploited in F5-K000159077?
F5-K000159077 can be exploited by parsing certain malformed extended headers in specific archive files.