https://seclists.org/oss-sec/2026/q2/110: GNU tar: listing/extraction desynchronization allows hidden file injection
Published Apr 12, 2026
·Updated
Affected Software
1 affected component
GNU GNU tar
Frequently Asked Questions
1
What is the severity of CVE-2026-12345?
The severity of CVE-2026-12345 is rated as high due to its potential for hidden file injection.
2
How do I fix CVE-2026-12345?
To fix CVE-2026-12345, update to the latest version of GNU tar where the vulnerability has been patched.
3
What systems are affected by CVE-2026-12345?
CVE-2026-12345 affects various systems using GNU tar for file listing and extraction functionalities.
4
What are the potential impacts of CVE-2026-12345?
The potential impacts of CVE-2026-12345 include unauthorized access and injection of hidden files that may compromise system security.
5
Is CVE-2026-12345 being actively exploited?
At the time of reporting, there have been no confirmed active exploitations of CVE-2026-12345, but it is advisable to apply patches promptly.