Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-6103— Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection

Quick assessment

Affected
PHP Group PHP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

phar_tar_number() 函数在解析 TAR 头部的八进制大小字段时,将其转换为 uint32_t 类型,但未进行溢出检查。该字段宽度为 11 个八进制位,可表示的最大值为 0x1FFFFFFFF;因此,当实际大小超过 0xFFFFFFFF 时,会发生静默截断(回绕)。解析器随后会错误地跳过相应数量的数据块,并将攻击者控制的文件内容误解释为下一个 TAR 头部。这种漏洞使得恶意构造的归档文件能够注入伪造的条目,导致 PharData 将这些条目报告并提取为合法内容,从而产生安全风险。

CVSS 4.3 · Medium EPSS 0.17% · P5

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-6103

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection
Source: CVE Program / CVE List V5
Vulnerability Description
phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF silently wraps. The parser then skips the wrong number of data blocks and interprets attacker-controlled file content as the next TAR header, which lets a crafted archive inject entries that PharData reports and extracts as if they were genuine.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
整数溢出或超界折返
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
PHP Group PHP 8.2.* ~ 8.2.34 -

II. Public POCs for CVE-2026-6103

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-6103

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-6103 (1)

Same Patch Batch · PHP Group · 2026-09-25 · 11 CVEs total

CVE-2026-91765 7.5 HIGH SOAP: Unbounded Recursion in Server-Side cleanup_xml_node
CVE-2026-17545 6.9 MEDIUM PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can ca
CVE-2026-91767 6.5 MEDIUM Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard
CVE-2026-91768 6.5 MEDIUM IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcm
CVE-2025-14181 6.5 MEDIUM Integer overflow to buffer overflow in soap HTTP parsing
CVE-2026-92842 5.9 MEDIUM OOB read / info leak in convert.* stream filters when line-break-chars contains NUL
CVE-2026-91766 5.9 MEDIUM Cross-origin credential leak in HTTP stream wrapper redirects
CVE-2026-93682 5.8 MEDIUM Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Loca
CVE-2026-91769 4.3 MEDIUM TLS Hostname Verification Falls Back to CN After SAN Mismatch
CVE-2025-1218 3.4 LOW Various packet overreads in mysqlnd_writeprotocol.c

IV. Related Vulnerabilities

V. Comments for CVE-2026-6103

No comments yet


Leave a comment