Issued at: 2026-09-01
Updated at: 2026-09-02
Advisory content derived from Red Hat RHSA-2026:61581, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Moderate: tar security, bug fix, and enhancement update
Description
The GNU tar program can save multiple files in an archive and restore files from an archive.
Security Fix(es):
* tar: tar: Hidden file injection via crafted archives (CVE-2026-5704)
* tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape (CVE-2026-18477)
* tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite (CVE-2026-18508)
Bug Fix(es) and Enhancement(s):
* tar: --one-top-level with absolute path fails [rhel-9] (JIRA:Rocky Linux-144021)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.