Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5704

Опубликовано: 06 апр. 2026
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

Меры по смягчению последствий

To mitigate this issue, avoid extracting archives from untrusted sources. If processing untrusted archives is necessary, do so within a sandboxed environment to limit potential impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6tarFix deferred
Red Hat Enterprise Linux 7tarFix deferred
Red Hat Enterprise Linux 8tarFix deferred
Red Hat Enterprise Linux 10tarFixedRHSA-2026:6158601.09.2026
Red Hat Enterprise Linux 9tarFixedRHSA-2026:6158131.08.2026
Red Hat Discovery 2discovery/discovery-server-rhel9FixedRHSA-2026:6178331.08.2026
Red Hat Hardened Imagestar-main-1.35-10.hum1FixedRHSA-2026:6651410.09.2026
Red Hat Update Infrastructure 5rhui5/cds-kubernetes-rhel9FixedRHSA-2026:6601809.09.2026
Red Hat Update Infrastructure 5rhui5/cds-rhel9FixedRHSA-2026:6601809.09.2026
Red Hat Update Infrastructure 5rhui5/haproxy-rhel9FixedRHSA-2026:6601809.09.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-434
https://bugzilla.redhat.com/show_bug.cgi?id=2455360tar: tar: Hidden file injection via crafted archives

EPSS

Процентиль: 34%
0.00401
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
6 месяцев назад

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

CVSS3: 5
nvd
6 месяцев назад

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

msrc
17 дней назад

Tar: tar: hidden file injection via crafted archives

CVSS3: 5
debian
6 месяцев назад

A flaw was found in tar. A remote attacker could exploit this vulnerab ...

suse-cvrf
3 месяца назад

Security update for tar

EPSS

Процентиль: 34%
0.00401
Низкий

5 Medium

CVSS3