{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos6els/vex/2025/cve-2025-64118-els_os-centos6els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-28T14:26:17Z",
      "generator": {
        "date": "2026-07-28T14:26:16Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2025-64118-ELS_OS-CENTOS6ELS",
      "initial_release_date": "2025-10-30T17:50:00Z",
      "revision_history": [
        {
          "date": "2025-10-30T17:50:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-28T01:20:41Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-07-28T14:26:17Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2025-64118"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 6",
                "product": {
                  "name": "Community Enterprise Operating System 6",
                  "product_id": "CentOS-6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "tar-2:1.23-15.el6_8.x86_64",
                "product": {
                  "name": "tar-2:1.23-15.el6_8.x86_64",
                  "product_id": "tar-2:1.23-15.el6_8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/tar@1.23-15.el6_8?arch=x86_64&epoch=2"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "tar-2:1.23-15.el6_8.tuxcare.els1.x86_64",
                "product": {
                  "name": "tar-2:1.23-15.el6_8.tuxcare.els1.x86_64",
                  "product_id": "tar-2:1.23-15.el6_8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/tar@1.23-15.el6_8.tuxcare.els1?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "tar-2:1.23-15.el6_8.tuxcare.els2.x86_64",
                "product": {
                  "name": "tar-2:1.23-15.el6_8.tuxcare.els2.x86_64",
                  "product_id": "tar-2:1.23-15.el6_8.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/tar@1.23-15.el6_8.tuxcare.els2?arch=x86_64&epoch=2"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-2:1.23-15.el6_8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:tar-2:1.23-15.el6_8.tuxcare.els1.x86_64"
        },
        "product_reference": "tar-2:1.23-15.el6_8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-2:1.23-15.el6_8.tuxcare.els2.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:tar-2:1.23-15.el6_8.tuxcare.els2.x86_64"
        },
        "product_reference": "tar-2:1.23-15.el6_8.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-2:1.23-15.el6_8.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:tar-2:1.23-15.el6_8.x86_64"
        },
        "product_reference": "tar-2:1.23-15.el6_8.x86_64",
        "relates_to_product_reference": "CentOS-6"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-64118",
      "cwe": {
        "id": "CWE-367",
        "name": "Time-of-check Time-of-use (TOCTOU) Race Condition"
      },
      "notes": [
        {
          "category": "description",
          "text": "node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "CentOS-6:tar-2:1.23-15.el6_8.tuxcare.els1.x86_64",
          "CentOS-6:tar-2:1.23-15.el6_8.tuxcare.els2.x86_64",
          "CentOS-6:tar-2:1.23-15.el6_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-64118"
        }
      ],
      "release_date": "2025-10-30T17:50:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-28T12:32:21.343298Z",
          "details": "This bug only manifests when an application explicitly uses tar.t/.list with sync: true and then reads entry bodies (e.g., in onReadEntry); other node‑tar methods like extract are unaffected. Exploitation further requires a precise local race where the on‑disk tar is truncated to a smaller size at exactly the right moment and boundary during parsing, and any leaked bytes are only exposed if the application surfaces that data. Given the local attack vector, high complexity, non‑default API usage, and reliance on application behavior to disclose data, the practical risk in managed server/VM environments is low and this CVE can be deprioritized.",
          "product_ids": [
            "CentOS-6:tar-2:1.23-15.el6_8.tuxcare.els1.x86_64",
            "CentOS-6:tar-2:1.23-15.el6_8.tuxcare.els2.x86_64",
            "CentOS-6:tar-2:1.23-15.el6_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "CentOS-6:tar-2:1.23-15.el6_8.tuxcare.els1.x86_64",
            "CentOS-6:tar-2:1.23-15.el6_8.tuxcare.els2.x86_64",
            "CentOS-6:tar-2:1.23-15.el6_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}