https://seclists.org/oss-sec/2026/q2/108: GNU tar: listing/extraction desynchronization allows hidden file injection
Published Apr 12, 2026
·Updated
Affected Software
1 affected component
GNU GNU tar=1.35
Frequently Asked Questions
1
What is the severity of CVE-2026-2078?
CVE-2026-2078 has been classified as a high severity vulnerability due to the potential for hidden file injection.
2
How do I fix CVE-2026-2078?
To fix CVE-2026-2078, update GNU tar to a version that addresses the signed integer overflow issue.
3
What systems are affected by CVE-2026-2078?
CVE-2026-2078 affects all versions of GNU tar prior to the patched release.
4
What is the risk of not addressing CVE-2026-2078?
Failure to address CVE-2026-2078 may allow attackers to inject hidden files, posing serious security risks.
5
What kind of attack can CVE-2026-2078 enable?
CVE-2026-2078 can enable attacks that exploit the listing/extraction desynchronization to manipulate file contents.