Описание
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.
Меры по смягчению последствий
To mitigate this issue, avoid extracting archives from untrusted sources. If processing untrusted archives is necessary, do so within a sandboxed environment to limit potential impact.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | tar | Fix deferred | ||
| Red Hat Enterprise Linux 7 | tar | Fix deferred | ||
| Red Hat Enterprise Linux 8 | tar | Fix deferred | ||
| Red Hat Enterprise Linux 10 | tar | Fixed | RHSA-2026:61586 | 01.09.2026 |
| Red Hat Enterprise Linux 9 | tar | Fixed | RHSA-2026:61581 | 31.08.2026 |
| Red Hat Discovery 2 | discovery/discovery-server-rhel9 | Fixed | RHSA-2026:61783 | 31.08.2026 |
| Red Hat Hardened Images | tar-main-1.35-10.hum1 | Fixed | RHSA-2026:66514 | 10.09.2026 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-rhel9 | Fixed | RHSA-2026:66018 | 09.09.2026 |
| Red Hat Update Infrastructure 5 | rhui5/cds-rhel9 | Fixed | RHSA-2026:66018 | 09.09.2026 |
| Red Hat Update Infrastructure 5 | rhui5/haproxy-rhel9 | Fixed | RHSA-2026:66018 | 09.09.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS3
Связанные уязвимости
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.
A flaw was found in tar. A remote attacker could exploit this vulnerab ...
EPSS
5 Medium
CVSS3