Issued at: 2026-09-24
Updated at: 2026-09-24
Advisory content derived from Red Hat RHSA-2026:70390, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Moderate: tar security, bug fix, and enhancement update
Description
The GNU tar program can save multiple files in an archive and restore files from an archive.
Security Fix(es):
* tar: Tar path traversal (CVE-2025-45582)
* tar: tar: Hidden file injection via crafted archives (CVE-2026-5704)
* tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape (CVE-2026-18477)
* tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite (CVE-2026-18508)
Bug Fix(es) and Enhancement(s):
* tar: --one-top-level with absolute path fails [rhel-8.10.z] (JIRA:Rocky Linux-144019)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.