Source: tar
Version: 1.35+dfsg-4
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for tar.

At point of writing this bugreport only the Red Hat bugzilla entries
are avaiable, can you check upstream, is this reported, is it fixed
already?

CVE-2026-18508[0]:
| A flaw was found in GNU tar. When extracting an archive with the
| --one-top-level option, hardlink targets are not confined to the
| designated top-level directory and may resolve relative to the
| extraction working directory. A crafted archive can create hardlinks
| that escape the intended boundary and, when combined with a
| preexisting symbolic link under the working directory, may allow
| writing outside that boundary during a single extraction.


CVE-2026-18477[1]:
| A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's
| incremental dumpdir 'X' rename handling allows a local attacker with
| write access to a directory being backed up to influence the restore
| process if the attacker has access to the system where the restore
| is being performed. During restoration, files or directories may be
| created, renamed or overwritten outside the intended extraction
| directory. This could lead to unauthorized file modification or, in
| some cases, privilege escalation. Exploitation does not require the
| attacker to modify or craft the archive, and standard backup and
| restore workflows—including extracting into a newly created
| directory without using the -P option do not mitigate the issue.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-18508
    https://www.cve.org/CVERecord?id=CVE-2026-18508
    https://bugzilla.redhat.com/show_bug.cgi?id=2509843
[1] https://security-tracker.debian.org/tracker/CVE-2026-18477
    https://www.cve.org/CVERecord?id=CVE-2026-18477
    https://bugzilla.redhat.com/show_bug.cgi?id=2509735

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to