Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5704

Опубликовано: 06 апр. 2026
Источник: redhat
CVSS3: 5

Описание

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

Меры по смягчению последствий

To mitigate this issue, avoid extracting archives from untrusted sources. If processing untrusted archives is necessary, do so within a sandboxed environment to limit potential impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tarFix deferred
Red Hat Enterprise Linux 6tarFix deferred
Red Hat Enterprise Linux 7tarFix deferred
Red Hat Enterprise Linux 8tarFix deferred
Red Hat Enterprise Linux 9tarFix deferred
Red Hat Hardened ImagestarAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-434
https://bugzilla.redhat.com/show_bug.cgi?id=2455360tar: tar: Hidden file injection via crafted archives

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
8 дней назад

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

CVSS3: 5
nvd
8 дней назад

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

CVSS3: 5
debian
8 дней назад

A flaw was found in tar. A remote attacker could exploit this vulnerab ...

CVSS3: 5
github
8 дней назад

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

5 Medium

CVSS3