[Apollo] Advisories Statistics light light Login

RLSA-2026:30856

Security Mirrored from RHSA-2026:30856
Issued at: 2026-07-01
Updated at: 2026-07-01

Synopsis

Important: perl-Archive-Tar security update



Description

Archive::Tar provides an object oriented mechanism for handling tar files. It provides class methods for quick and easy files handling while also allowing for the creation of tar file objects for custom manipulation. If you have the IO::Zlib module installed, Archive::Tar will also support compressed or gzipped tar files.

Security Fix(es):

* perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access (CVE-2026-42496)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 9 aarch64 Rocky Linux 9 ppc64le Rocky Linux 9 s390x Rocky Linux 9 x86_64

Fixes

2481314

CVEs

CVE-2026-42496

Affected packages

Rocky Linux 9 x86_64 - AppStream

perl-Archive-Tar-0:2.38-6.el9_8.1.noarch.rpm perl-Archive-Tar-0:2.38-6.el9_8.1.src.rpm

Rocky Linux 9 aarch64 - AppStream

perl-Archive-Tar-0:2.38-6.el9_8.1.noarch.rpm perl-Archive-Tar-0:2.38-6.el9_8.1.src.rpm

Rocky Linux 9 s390x - AppStream

perl-Archive-Tar-0:2.38-6.el9_8.1.noarch.rpm perl-Archive-Tar-0:2.38-6.el9_8.1.src.rpm

Rocky Linux 9 ppc64le - AppStream

perl-Archive-Tar-0:2.38-6.el9_8.1.noarch.rpm perl-Archive-Tar-0:2.38-6.el9_8.1.src.rpm