An update is available for tar. This update affects Rocky Linux 9. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list
The GNU tar program can save multiple files in an archive and restore files from an archive. Security Fix(es): * tar: heap buffer overflow at from_header() in list.c via specially crafted checksum (CVE-2022-48303) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
tar-2:1.34-6.el9_1.aarch64.rpm
tar-2:1.34-6.el9_1.ppc64le.rpm
tar-2:1.34-6.el9_1.s390x.rpm
tar-2:1.34-6.el9_1.src.rpm
tar-2:1.34-6.el9_1.x86_64.rpm
tar-debuginfo-2:1.34-6.el9_1.aarch64.rpm
tar-debuginfo-2:1.34-6.el9_1.ppc64le.rpm
tar-debuginfo-2:1.34-6.el9_1.s390x.rpm
tar-debuginfo-2:1.34-6.el9_1.x86_64.rpm
tar-debugsource-2:1.34-6.el9_1.aarch64.rpm
tar-debugsource-2:1.34-6.el9_1.ppc64le.rpm
tar-debugsource-2:1.34-6.el9_1.s390x.rpm
tar-debugsource-2:1.34-6.el9_1.x86_64.rpm
No References
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48303
https://bugzilla.redhat.com/show_bug.cgi?id=2149722