Source: rust-tar Version: 0.4.45-2 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for rust-tar. At point of writing there was only the gist at [1], can you check with upstream if this is known/reported/fixed? CVE-2026-70622[0]: | tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape | vulnerability in the Builder::append_dir_all() function that allows | attackers to read files outside the intended source root directory | by planting symlinks in an attacker-controlled directory. When a | privileged process archives an untrusted directory, the function | follows symlinks without verifying that resolved targets remain | within the source root, causing out-of-bounds files to be included | in the archive as regular files and disclosed to the attacker. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-70622 https://www.cve.org/CVERecord?id=CVE-2026-70622 [1] https://gist.github.com/thesmartshadow/e7dac0bb690ee17b9cc142154cb11726 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

