https://seclists.org/oss-sec/2026/q2/106: GNU tar: listing/extraction desynchronization allows hidden file injection
Published Apr 12, 2026
·Updated
Affected Software
1 affected component
GNU GNU tar
Frequently Asked Questions
1
What is the severity of GNU tar: listing/extraction desynchronization allows hidden file injection?
The severity of GNU tar: listing/extraction desynchronization allows hidden file injection is classified as high.
2
How do I fix GNU tar: listing/extraction desynchronization allows hidden file injection?
To fix GNU tar: listing/extraction desynchronization allows hidden file injection, update to the latest version of GNU tar.
3
What are the potential consequences of GNU tar: listing/extraction desynchronization allows hidden file injection?
The potential consequences include unauthorized access and extraction of hidden files, which may lead to data breaches.
4
Who is affected by GNU tar: listing/extraction desynchronization allows hidden file injection?
Users and organizations utilizing affected versions of GNU tar are at risk from this vulnerability.
5
Is there a workaround for GNU tar: listing/extraction desynchronization allows hidden file injection?
While updating is the best solution, temporarily restricting access to the GNU tar tool may serve as a workaround.