tar-1.34-13.el9_8

エラータID: AXSA:2026-1733:03

Release date: 
Wednesday, September 2, 2026 - 15:42
Subject: 
tar-1.34-13.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The GNU tar program can save multiple files in an archive and restore files from an archive.

Security Fix(es):

* tar: tar: Hidden file injection via crafted archives (CVE-2026-5704)
* tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape (CVE-2026-18477)
* tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite (CVE-2026-18508)

Bug Fix(es) and Enhancement(s):

* tar: --one-top-level with absolute path fails [rhel-9] (JIRA:RHEL-144021)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-18477
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
CVE-2026-18508
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
CVE-2026-5704
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. tar-1.34-13.el9_8.src.rpm
    MD5: e61058fea6ba628b2bcfafa789b633d8
    SHA-256: 81d41646ac750bdcc723d63e06acfdbe6a2d0ea831189fdb606ca572423b3da8
    Size: 2.20 MB

Asianux Server 9 for x86_64
  1. tar-1.34-13.el9_8.x86_64.rpm
    MD5: 375af3da1388453f2234b90e585ef6b0
    SHA-256: 212f49cf1a7d1167ab8a898a71c03ea17bdc21c46fc6585466c6d1d1fb7aabe9
    Size: 888.93 kB