{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-6103","assignerOrgId":"dd77f84a-d19a-4638-8c3d-a322d820ed2b","state":"PUBLISHED","assignerShortName":"php","dateReserved":"2026-04-11T04:13:04.238Z","datePublished":"2026-09-25T20:08:49.333Z","dateUpdated":"2026-09-25T20:41:27.115Z"},"containers":{"cna":{"providerMetadata":{"orgId":"dd77f84a-d19a-4638-8c3d-a322d820ed2b","shortName":"php","dateUpdated":"2026-09-25T20:21:07.070Z"},"title":"Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-190","description":"CWE-190 Integer overflow or wraparound","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-92","descriptions":[{"lang":"en","value":"CAPEC-92 Forced Integer Overflow"}]}],"affected":[{"vendor":"PHP Group","product":"PHP","versions":[{"status":"affected","version":"8.2.*","lessThan":"8.2.34","versionType":"semver"},{"status":"affected","version":"8.3.*","lessThan":"8.3.35","versionType":"semver"},{"status":"affected","version":"8.4.*","lessThan":"8.4.26","versionType":"semver"},{"status":"affected","version":"8.5.*","lessThan":"8.5.11","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF silently wraps. The parser then skips the wrong number of data blocks and interprets attacker-controlled file content as the next TAR header, which lets a crafted archive inject entries that PharData reports and extracts as if they were genuine.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p><code>phar_tar_number()</code> parses the octal size field of a TAR header into a <code>uint32_t</code> with no overflow check. The field is 11 octal digits wide and holds values up to <code>0x1FFFFFFFF</code>, so a size above <code>0xFFFFFFFF</code> silently wraps. The parser then skips the wrong number of data blocks and interprets attacker-controlled file content as the next TAR header, which lets a crafted archive inject entries that <code>PharData</code> reports and extracts as if they were genuine.</p>"}]}],"references":[{"url":"https://github.com/php/php-src/security/advisories/GHSA-j3wh-g957-2m85","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseSeverity":"MEDIUM","baseScore":4.3,"vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"}}],"credits":[{"lang":"en","value":"@arnoldasr (GitHub)","type":"reporter"},{"lang":"en","value":"@Oblivionsage (GitHub)","type":"reporter"},{"lang":"en","value":"@OSTIF-Derek (GitHub)","type":"reporter"},{"lang":"en","value":"Jakub Zelenka","type":"remediation developer"},{"lang":"en","value":"Weilin Du","type":"remediation reviewer"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.5"}},"adp":[{"references":[{"url":"https://github.com/php/php-src/security/advisories/GHSA-j3wh-g957-2m85","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-25T20:41:05.626504Z","id":"CVE-2026-6103","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-25T20:41:27.115Z"}}]}}