Source: golang-github-moby-go-archive Version: 0.2.0-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for golang-github-moby-go-archive. CVE-2026-17106[0]: | The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, | Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine | filesystem operations to the destination directory. The extractor | decides where each archive entry lands using lexical string checks | and then performs the filesystem operation on a path that is | resolved by the OS, so links introduced by the archive can be | followed out of the destination directory. An attacker who controls | the contents of an archive can create or overwrite files at | arbitrary paths writable by the extracting process. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-17106 https://www.cve.org/CVERecord?id=CVE-2026-17106 [1] https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h Please adjust the affected versions in the BTS as needed. Regards, Salvatore

