Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
tar could be made to overwrite files if it opened a specially crafted archive.. ========================================================================== Ubuntu Security Notice USN-8477-1 June 25, 2026 tar vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: tar could be made to overwrite files if it opened a specially crafted archive. Software Description: - tar: GNU tar archive utility Details: It was discovered that tar incorrectly handled certain crafted archive files. An attacker could possibly use this to inject hidden files with attacker-controlled content, bypassing pre-extraction inspection mechanisms. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS tar 1.35+dfsg-4ubuntu0.1 Ubuntu 24.04 LTS tar 1.35+dfsg-3ubuntu0.1 Ubuntu 22.04 LTS tar 1.34+dfsg-1ubuntu0.1.22.04.3 Ubuntu 20.04 LTS tar 1.30+dfsg-7ubuntu0.20.04.4+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS tar 1.29b-2ubuntu0.4+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS tar 1.28-2.1ubuntu0.2+esm4 Available with Ubuntu Pro Ubuntu 14.04 LTS tar 1.27.1-1ubuntu0.1+esm5 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8477-1 CVE-2026-5704 Package Information: https://launchpad.net/ubuntu/+source/tar/1.35+dfsg-4ubuntu0.1 https://launchpad.net/ubuntu/+source/tar/1.35+dfsg-3ubuntu0.1 https://launchpad.net/ubuntu/+source/tar/1.34+dfsg-1ubuntu0.1.22.04.3 . Ubuntu's tar utility faces a critical flaw allowing file overwrites via crafted archives. Update your system now.. Ubuntu Tar Security Update, Critical Tar Vulnerability, Secure File Archiving. . Severity: Critical. LinuxSecurity.com Team
Update rust-astral-tokio-tar to 0.6.0, fixing CVE-2026-32766. Update rust-tar to 0.4.45, fixing CVE-2026-33056. Update rust-nix to 0.31.2. Update uv and python- uv-build to 0.10.2, rebuilding them with the latest rust-astral-tokio-tar and rust-tar. Update python-fastar to 0.9.0, rebuilding it with the lastest rust- tar. Rebuild maturin with the latest rust-tar.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-23bb71ea52 2026-03-29 01:07:01.422539+00:00 -------------------------------------------------------------------------------- Name : rust-astral-tokio-tar Product : Fedora 42 Version : 0.6.0 Release : 1.fc42 URL : https://crates.io/crates/astral-tokio-tar Summary : Rust implementation of an async TAR file reader and writer Description : A Rust implementation of an async TAR file reader and writer. This library does not currently handle compression, but it is abstract over all I/O readers and writers. Additionally, great lengths are taken to ensure that the entire contents are never required to be entirely resident in memory all at once. -------------------------------------------------------------------------------- Update Information: Update rust-astral-tokio-tar to 0.6.0, fixing CVE-2026-32766. Update rust-tar to 0.4.45, fixing CVE-2026-33056. Update rust-nix to 0.31.2. Update uv and python- uv-build to 0.10.2, rebuilding them with the latest rust-astral-tokio-tar and rust-tar. Update python-fastar to 0.9.0, rebuilding it with the lastest rust- tar. Rebuild maturin with the latest rust-tar. -------------------------------------------------------------------------------- ChangeLog: * Mon Mar 16 2026 Benjamin A. Beasley - 0.6.0-1 - Update to version 0.6.0; Fixes RHBZ#2448054 * Sat Jan 17 2026 Fedora Release Engineering - 0.5.6-2 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2448054 - rust-astral-tokio-tar-0.6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2448054 [ 2 ] Bug #2449243 - uv-0.10.12 is available https://bugzilla.redhat.com/show_bug.cgi?id=2449243 [ 3 ] Bug #2449274 - rust-tar-0.4.45 is available https://bugzilla.redhat.com/show_bug.cgi?id=2449274 [ 4 ] Bug #2449338 - python-uv-build-0.10.12 is available https://bugzilla.redhat.com/show_bug.cgi?id=2449338 [ 5 ] Bug #2449547 - CVE-2026-32766 python-uv-build: astral-tokio-tar: Potential archive misinterpretation via malformed PAX extensions [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2449547 [ 6 ] Bug #2449549 - CVE-2026-32766 uv: astral-tokio-tar: Potential archive misinterpretation via malformed PAX extensions [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2449549 [ 7 ] Bug #2449645 - python-fastar-0.9.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2449645 [ 8 ] Bug #2449681 - CVE-2026-33056 maturin: tar-rs: Arbitrary directory permission modification via crafted tar archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449681 [ 9 ] Bug #2449683 - CVE-2026-33056 python-fastar: tar-rs: Arbitrary directory permission modification via crafted tar archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449683 [ 10 ] Bug #2449684 - CVE-2026-33056 python-uv-build: tar-rs: Arbitrary directory permission modification via crafted tar archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449684 [ 11 ] Bug #2449694 - CVE-2026-33056 uv: tar-rs: Arbitrary directory permission modification via crafted tar archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449694 -------------------------------------------------------------------------------- Thisupdate can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-23bb71ea52' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.