Description:
The GNU tar program can save multiple files in an archive and restore files from an archive.
Security Fix(es):
* tar: Tar path traversal (CVE-2025-45582)
* tar: tar: Hidden file injection via crafted archives (CVE-2026-5704)
* tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape (CVE-2026-18477)
* tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite (CVE-2026-18508)
Bug Fix(es) and Enhancement(s):
* tar: --one-top-level with absolute path fails [almalinux-8.10.z] (JIRA:AlmaLinux-144019)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
tar-1.30-13.el8_10.aarch64.rpm |
2535acf17c8cc9ec3d5b7fd47ed46483190098231c60f0b4edf819cdffbd2fcb |
| ppc64le |
tar-1.30-13.el8_10.ppc64le.rpm |
0dbbc9c49663aa34cf6122d1b799469edfc7bab830660b01618a72b7857ff99e |
| s390x |
tar-1.30-13.el8_10.s390x.rpm |
bf1adced51cc5aadccfef3d29453357442b279979e4a13b53fddd63993e05833 |
| x86_64 |
tar-1.30-13.el8_10.x86_64.rpm |
056181e5e2754670f54947c073694989385b4706860b976e2e0ed232e1ea8b1c |