Public bug reported:

A new release of tar is available for merging from Debian.

Ubuntu Proposed: 1.35+dfsg-4ubuntu2
Debian Unstable: 1.35+dfsg-5

### New Debian Changes ###

tar (1.35+dfsg-5) unstable; urgency=medium

  * Team upload (salsa.debian.org/debian namespace)
  * Add libacl FTBFS fix from bug-tar mailing list (Closes: #1141146)
  * Slight tweak of upstream patch to apply cleanly to 1.35

 -- Simon Josefsson <[email protected]>  Sat, 01 Aug 2026 14:00:00
+0200


### Old Ubuntu Delta ###

tar (1.35+dfsg-4ubuntu2) stonking; urgency=medium

  [ Leonidas Da Silva Barbosa ]
  * SECURITY REGRESSION: Extract files issue
    - debian/patches/CVE-2026-5704-*.patch: address a regression
      that makes valid files not extract in src/list.c,
      tests/Makefile.am, tests/extrac32.at, tests/extrac34.at,
      test/testsuite.at, src/extract.c, tests/extract23,
      tests/extrac30.at (LP: #2160650).
  * SECURITY REGRESSION: Old archives with nonzero directory sizes
    failing to be extracted
    - debian/patches/CVE-2026-5704-5.patch: fix this by forcing
      the size to zero for DIRTYPE in read_header() in src/list.c
      (LP: #2161311)

 -- Marc Deslauriers <[email protected]>  Mon, 27 Jul 2026
12:58:33 -0400

tar (1.35+dfsg-4ubuntu1) stonking; urgency=medium

  [ Leonidas Da Silva Barbosa ]
  * SECURITY UPDATE: file injection via crafted archive
    - debian/patches/CVE-2026-5704.patch: always call skip_member() after
      extraction in src/extract.c, fix skim_member() to skip directory data
      in src/list.c, remove conditional skip_member() call from
      purge_directory in src/incremen.c
    - CVE-2026-5704

  [ Marc Deslauriers ]
  * SECURITY UPDATE: File overwrite via directory traversal
    - debian/patches/CVE-2025-45582-*.patch: Backport openat2 support in
      order to jailify the extraction directory.
    - CVE-2025-45582

 -- Marc Deslauriers <[email protected]>  Mon, 29 Jun 2026
07:52:01 -0400

** Affects: tar (Ubuntu)
     Importance: Wishlist
         Status: New


** Tags: dcr-merge

** Changed in: tar (Ubuntu)
   Importance: Undecided => Wishlist

** Changed in: tar (Ubuntu)
    Milestone: None => ubuntu-26.05

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163533

Title:
  Merge tar 1.35+dfsg-5 from Debian for stonking cycle

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/tar/+bug/2163533/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to