https://seclists.org/oss-sec/2026/q2/107: GNU tar: listing/extraction desynchronization allows hidden file injection
Published Apr 12, 2026
·Updated
Affected Software
1 affected component
GNU GNU tar=1.35
Frequently Asked Questions
1
What is the severity of GNU tar: listing/extraction desynchronization allows hidden file injection?
The severity of GNU tar: listing/extraction desynchronization allows hidden file injection is considered high due to the potential for unauthorized file access.
2
How do I fix GNU tar: listing/extraction desynchronization allows hidden file injection?
To fix GNU tar: listing/extraction desynchronization allows hidden file injection, ensure you update to the latest version provided by the GNU project.
3
What systems are affected by GNU tar: listing/extraction desynchronization allows hidden file injection?
The vulnerability affects all systems running vulnerable versions of GNU tar.
4
What are the potential implications of GNU tar: listing/extraction desynchronization allows hidden file injection?
The implications include the possibility of hidden file injection, leading to unauthorized data manipulation or access.
5
When was GNU tar: listing/extraction desynchronization allows hidden file injection published?
GNU tar: listing/extraction desynchronization allows hidden file injection was published on April 12, 2026.