Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2714-1

Опубликовано: 30 июн. 2026
Источник: suse-cvrf

Описание

Security update for tar

This update for tar fixes the following issues

Security fixes:

  • CVE-2026-5704: crafted archives can be used to to hide file injection (bsc#1261900).

Other fixes:

  • Fix tar changing dir permissions temporarily even when using --no-overwrite-dir.
  • Fix --dereference/-h not working properly after CVE-2025-45582 fix (bsc#1265450).
  • Fix extraction failure for paths like 'a/./b' caused by the gnulib openat2 implementation (bsc#1267189).

Список пакетов

Container bci/bci-sle15-kernel-module-devel:latest
tar-1.34-150000.3.42.1
Container bci/spack:latest
tar-1.34-150000.3.42.1
Container suse/ltss/sle15.4/sle15:latest
tar-1.34-150000.3.42.1
Container suse/ltss/sle15.5/sle15:latest
tar-1.34-150000.3.42.1
Container suse/ltss/sle15.6/sle15:latest
tar-1.34-150000.3.42.1
Container suse/postgres:16
tar-1.34-150000.3.42.1
Container suse/postgres:16.14
tar-1.34-150000.3.42.1
Container suse/postgres:17
tar-1.34-150000.3.42.1
Container suse/postgres:17.10
tar-1.34-150000.3.42.1
Container suse/postgres:latest
tar-1.34-150000.3.42.1
Container suse/sle-micro-rancher/5.3:latest
tar-1.34-150000.3.42.1
Container suse/sle-micro-rancher/5.4:latest
tar-1.34-150000.3.42.1
Container suse/sle-micro/5.3/toolbox:latest
tar-1.34-150000.3.42.1
Container suse/sle-micro/5.4/toolbox:latest
tar-1.34-150000.3.42.1
Container suse/sle-micro/5.5/toolbox:latest
tar-1.34-150000.3.42.1
Container suse/sle-micro/5.5:latest
tar-1.34-150000.3.42.1
Container suse/sle-micro/base-5.5:latest
tar-1.34-150000.3.42.1
Image SLES15-SP4-CHOST-BYOS
tar-1.34-150000.3.42.1
Image SLES15-SP4-CHOST-BYOS-Aliyun
tar-1.34-150000.3.42.1
Image SLES15-SP4-CHOST-BYOS-Azure
tar-1.34-150000.3.42.1
Image SLES15-SP4-CHOST-BYOS-EC2
tar-1.34-150000.3.42.1
Image SLES15-SP4-CHOST-BYOS-GCE
tar-1.34-150000.3.42.1
Image SLES15-SP4-CHOST-BYOS-SAP-CCloud
tar-1.34-150000.3.42.1
Image SLES15-SP4-SAP
tar-1.34-150000.3.42.1
Image SLES15-SP4-SAP-Azure
tar-1.34-150000.3.42.1
Image SLES15-SP4-SAP-GCE
tar-1.34-150000.3.42.1
Image SLES15-SP4-SAPCAL
tar-1.34-150000.3.42.1
Image SLES15-SP4-SAPCAL-Azure
tar-1.34-150000.3.42.1
Image SLES15-SP4-SAPCAL-GCE
tar-1.34-150000.3.42.1
Image SLES15-SP5-SAPCAL-Azure
tar-1.34-150000.3.42.1
Image SLES15-SP5-SAPCAL-EC2
tar-1.34-150000.3.42.1
Image SLES15-SP5-SAPCAL-GCE
tar-1.34-150000.3.42.1
Image SLES15-SP6-SAP-BYOS
tar-1.34-150000.3.42.1
Image SLES15-SP6-SAP-BYOS-EC2
tar-1.34-150000.3.42.1
Image SLES15-SP6-SAP-Hardened-BYOS
tar-1.34-150000.3.42.1
Image SLES15-SP6-SAP-Hardened-BYOS-EC2
tar-1.34-150000.3.42.1
Image SLES15-SP6-SAP-Hardened-EC2
tar-1.34-150000.3.42.1
Image SLES15-SP7-CHOST-BYOS-Aliyun
tar-1.34-150000.3.42.1
Image SLES15-SP7-CHOST-BYOS-Azure
tar-1.34-150000.3.42.1
Image SLES15-SP7-CHOST-BYOS-EC2
tar-1.34-150000.3.42.1
Image SLES15-SP7-CHOST-BYOS-GCE
tar-1.34-150000.3.42.1
Image SLES15-SP7-CHOST-BYOS-GDC
tar-1.34-150000.3.42.1
Image SLES15-SP7-CHOST-BYOS-SAP-CCloud
tar-1.34-150000.3.42.1
Image SLES15-SP7-EC2-ECS-HVM
tar-1.34-150000.3.42.1
Image SLES15-SP7-HPC-Azure
tar-1.34-150000.3.42.1
Image SLES15-SP7-HPC-BYOS-Azure
tar-1.34-150000.3.42.1
Image SLES15-SP7-HPC-BYOS-EC2
tar-1.34-150000.3.42.1
Image SLES15-SP7-HPC-BYOS-GCE
tar-1.34-150000.3.42.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
tar-1.34-150000.3.42.1
tar-lang-1.34-150000.3.42.1
tar-rmt-1.34-150000.3.42.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
tar-1.34-150000.3.42.1
tar-lang-1.34-150000.3.42.1
tar-rmt-1.34-150000.3.42.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
tar-1.34-150000.3.42.1
tar-lang-1.34-150000.3.42.1
tar-rmt-1.34-150000.3.42.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
tar-1.34-150000.3.42.1
tar-lang-1.34-150000.3.42.1
tar-rmt-1.34-150000.3.42.1
SUSE Linux Enterprise Micro 5.3
tar-1.34-150000.3.42.1
SUSE Linux Enterprise Micro 5.4
tar-1.34-150000.3.42.1
SUSE Linux Enterprise Micro 5.5
tar-1.34-150000.3.42.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
tar-1.34-150000.3.42.1
tar-lang-1.34-150000.3.42.1
tar-rmt-1.34-150000.3.42.1
SUSE Linux Enterprise Server 15 SP4-LTSS
tar-1.34-150000.3.42.1
tar-lang-1.34-150000.3.42.1
tar-rmt-1.34-150000.3.42.1
SUSE Linux Enterprise Server 15 SP5-LTSS
tar-1.34-150000.3.42.1
tar-lang-1.34-150000.3.42.1
tar-rmt-1.34-150000.3.42.1
SUSE Linux Enterprise Server 15 SP6-LTSS
tar-1.34-150000.3.42.1
tar-lang-1.34-150000.3.42.1
tar-rmt-1.34-150000.3.42.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
tar-1.34-150000.3.42.1
tar-lang-1.34-150000.3.42.1
tar-rmt-1.34-150000.3.42.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
tar-1.34-150000.3.42.1
tar-lang-1.34-150000.3.42.1
tar-rmt-1.34-150000.3.42.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
tar-1.34-150000.3.42.1
tar-lang-1.34-150000.3.42.1
tar-rmt-1.34-150000.3.42.1

Описание

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:latest:tar-1.34-150000.3.42.1
Container bci/spack:latest:tar-1.34-150000.3.42.1
Container suse/ltss/sle15.4/sle15:latest:tar-1.34-150000.3.42.1
Container suse/ltss/sle15.5/sle15:latest:tar-1.34-150000.3.42.1

Ссылки