RHSA-2026:61581: Moderate: tar security, bug fix, and enhancement update
Moderate: tar security, bug fix, and enhancement update
Other sources
The GNU tar program can save multiple files in an archive and restore files from an archive.Security Fix(es): tar: tar: Hidden file injection via crafted archives (CVE-2026-5704) tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape (CVE-2026-18477) tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite (CVE-2026-18508) Bug Fix(es) and Enhancement(s): tar: --one-top-level with absolute path fails [rhel-9] (JIRA:RHEL-144021) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/tarto a version that resolves this vulnerability.Fixed in 1.34-13.el9_8 - Upgrade
Upgrade
redhat/tar-debuginfoto a version that resolves this vulnerability.Fixed in 1.34-13.el9_8 - Upgrade
Upgrade
redhat/tar-debugsourceto a version that resolves this vulnerability.Fixed in 1.34-13.el9_8 - Upgrade
Upgrade
redhat/tarto a version that resolves this vulnerability.Fixed in 1.34-13.el9_8.aa - Upgrade
Upgrade
redhat/tar-debuginfoto a version that resolves this vulnerability.Fixed in 1.34-13.el9_8.aa - Upgrade
Upgrade
redhat/tar-debugsourceto a version that resolves this vulnerability.Fixed in 1.34-13.el9_8.aa - Upgrade
Upgrade
tarto a version that resolves this vulnerability.Patch JIRA:RHEL-144021 - Upgrade
Upgrade
tarto a version that resolves this vulnerability.Patch CVE-2026-18508 - Upgrade
Upgrade
tarto a version that resolves this vulnerability.Patch CVE-2026-18477 - Upgrade
Upgrade
tarto a version that resolves this vulnerability.Patch CVE-2026-5704
Event History
Frequently Asked Questions
Which RHEL deployments are covered by this advisory?
The advisory applies to specified Red Hat Enterprise Linux deployments on x86_64, Power little endian, IBM z Systems, and ARM 64. It also covers certain Extended Life Cycle, Extended Update Support, and Update Services for SAP Solutions offerings listed in the advisory.