Public bug reported: A new release of tar is available for merging from Debian.
Ubuntu Proposed: 1.35+dfsg-4ubuntu2 Debian Unstable: 1.35+dfsg-5 ### New Debian Changes ### tar (1.35+dfsg-5) unstable; urgency=medium * Team upload (salsa.debian.org/debian namespace) * Add libacl FTBFS fix from bug-tar mailing list (Closes: #1141146) * Slight tweak of upstream patch to apply cleanly to 1.35 -- Simon Josefsson <[email protected]> Sat, 01 Aug 2026 14:00:00 +0200 ### Old Ubuntu Delta ### tar (1.35+dfsg-4ubuntu2) stonking; urgency=medium [ Leonidas Da Silva Barbosa ] * SECURITY REGRESSION: Extract files issue - debian/patches/CVE-2026-5704-*.patch: address a regression that makes valid files not extract in src/list.c, tests/Makefile.am, tests/extrac32.at, tests/extrac34.at, test/testsuite.at, src/extract.c, tests/extract23, tests/extrac30.at (LP: #2160650). * SECURITY REGRESSION: Old archives with nonzero directory sizes failing to be extracted - debian/patches/CVE-2026-5704-5.patch: fix this by forcing the size to zero for DIRTYPE in read_header() in src/list.c (LP: #2161311) -- Marc Deslauriers <[email protected]> Mon, 27 Jul 2026 12:58:33 -0400 tar (1.35+dfsg-4ubuntu1) stonking; urgency=medium [ Leonidas Da Silva Barbosa ] * SECURITY UPDATE: file injection via crafted archive - debian/patches/CVE-2026-5704.patch: always call skip_member() after extraction in src/extract.c, fix skim_member() to skip directory data in src/list.c, remove conditional skip_member() call from purge_directory in src/incremen.c - CVE-2026-5704 [ Marc Deslauriers ] * SECURITY UPDATE: File overwrite via directory traversal - debian/patches/CVE-2025-45582-*.patch: Backport openat2 support in order to jailify the extraction directory. - CVE-2025-45582 -- Marc Deslauriers <[email protected]> Mon, 29 Jun 2026 07:52:01 -0400 ** Affects: tar (Ubuntu) Importance: Wishlist Status: New ** Tags: dcr-merge ** Changed in: tar (Ubuntu) Importance: Undecided => Wishlist ** Changed in: tar (Ubuntu) Milestone: None => ubuntu-26.05 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2163533 Title: Merge tar 1.35+dfsg-5 from Debian for stonking cycle To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/tar/+bug/2163533/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
