{"id":"CVE-2021-20193","title":"A flaw was found in the src/list.c of tar 1.33 and earlier","summary":"A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system avai…","severity":"low","cvss":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","cwe":["CWE-401","CWE-125","CWE-401"],"vendor":"gnu","product":"tar","affected":["tar <= 1.33"],"published":"2021-03-26","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:33.373","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-20193","references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1917565","label":"secalert@redhat.com"},{"url":"https://git.savannah.gnu.org/cgit/tar.git/commit/?id=d9d4435692150fa8ff68e1b1a473d187cc3fd777","label":"secalert@redhat.com"},{"url":"https://savannah.gnu.org/bugs/?59897","label":"secalert@redhat.com"},{"url":"https://security.gentoo.org/glsa/202105-29","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1917565","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.savannah.gnu.org/cgit/tar.git/commit/?id=d9d4435692150fa8ff68e1b1a473d187cc3fd777","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://savannah.gnu.org/bugs/?59897","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202105-29","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01092,"epssPercentile":0.64371,"ingestedAt":"2026-10-08T22:11:53.731Z","slug":"CVE-2021-20193","body":"## Overview\n\nA flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.\n\n## Affected\n\n- `tar <= 1.33`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":18,"depthScoreParts":{"impact":18.2,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}