Description:
The GNU tar program can save multiple files in an archive and restore files from an archive.
Security Fix(es):
* tar: tar: Hidden file injection via crafted archives (CVE-2026-5704)
* tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape (CVE-2026-18477)
* tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite (CVE-2026-18508)
Bug Fix(es) and Enhancement(s):
* tar: --one-top-level with absolute path fails (JIRA:AlmaLinux-143906)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
tar-1.35-13.el10_2.aarch64.rpm |
6019ab0050f811aad3189850eac2b57b976f910751e8403f6fe255dd2c7a132f |
| ppc64le |
tar-1.35-13.el10_2.ppc64le.rpm |
161e98077171f8d8351b6f3f4bd43690443ea6dc55936b16499ff386fc8afaec |
| s390x |
tar-1.35-13.el10_2.s390x.rpm |
c21f66961780670bf026a01e076a898ce411a0be0ce38b345edfbe2b2e30f900 |
| x86_64 |
tar-1.35-13.el10_2.x86_64.rpm |
b1b33a3f5d03c270f2e79f452b4384955faaabb697df52c2885d1247b02c0c65 |
| x86_64_v2 |
tar-1.35-13.el10_2.x86_64_v2.rpm |
b66f01bdbd7e2608097d227deddf0eb67772a7a090ed27702b908be2bee073c2 |