CVE-2026-32766: astral-tokio-tar insufficiently validates PAX extensions during extraction

Overview

Severity
N/A
Exploit Status
Not Exploited
Patch Tuesday
2026-Mar
Released
2026-03-21
Last Updated
2026-04-29
EPSS Score
0.02% (percentile: 3.8%)

Affected Products (3)

Open Source Software

  • azl3 kata-containers-cc 3.15.0.aks0-7 on Azure Linux 3.0
  • azl3 kata-containers-cc 3.15.0.aks0-8 on Azure Linux 3.0

Other

  • 21252-17084

Revision History

  • 2026-03-21: Information published.
  • 2026-03-31: Information published.
  • 2026-04-29: Information published.