It looks like tar developers are going to enforce --one-top-level to be
a relative directory:

https://github.com/praiskup/tar/commit/678dbc679a1478da58c884de509ab2844eb04cdb

While this does change behaviour, I'm not sure we should deviate from
upstream for the CVE-2026-5704 fix.


** CVE added: https://cve.org/CVERecord?id=CVE-2026-5704

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2160696

Title:
  Extraction fails when passing absolute directory to --one-top-level

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/tar/+bug/2160696/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to