RootCauseunvalidated
xattr_decoder() routine in src/xheader.c calls alloca() twice with sizes that come directly from the archive — all SCHILY.xattr.* keys take this path. Tension: Neither bound is validated.
f27df0d5-e100-42be-a764-4034313b586c
xattr_decoder() routine in src/xheader.c calls alloca() twice with sizes that come directly from the archive — all SCHILY.xattr.* keys take this path. Tension: Neither bound is validated.