<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:57:53.012825+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-30361</id>
    <title>EUVD-2026-30361</title>
    <updated>2026-10-03T15:57:53.119462+00:00</updated>
    <content>EUVD-2026-30361</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-30361"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-38511</id>
    <title>fkie_cve-2021-38511</title>
    <updated>2026-10-03T15:57:53.119502+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary directories via .. traversal.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-38511"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-62jx-8vmh-4mcw</id>
    <title>GHSA-62jx-8vmh-4mcw — Links in archive can create arbitrary directories</title>
    <updated>2026-10-03T15:57:53.119536+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: tar</p>
<p>When unpacking a tarball that contains a symlink the tar crate may create directories outside of the directory it's supposed to unpack into. The function errors when it's trying to create a file, but the folders are already created at this point.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-62jx-8vmh-4mcw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-38511</id>
    <title>gsd-2021-38511</title>
    <updated>2026-10-03T15:57:53.119562+00:00</updated>
    <content>gsd-2021-38511</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-38511"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2021-0080</id>
    <title>RUSTSEC-2021-0080 — Links in archive can create arbitrary directories</title>
    <updated>2026-10-03T15:57:53.119575+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: tar</p>
<p>When unpacking a tarball that contains a symlink the `tar` crate may create
directories outside of the directory it's supposed to unpack into.</p>
<p>The function errors when it's trying to create a file, but the folders are
already created at this point.</p>
<p>```rust
use std::{io, io::Result};
use tar::{Archive, Builder, EntryType, Header};</p>
<p>fn main() -&gt; Result&lt;()&gt; {
    let mut buf = Vec::new();</p>
<p>{
        let mut builder = Builder::new(&amp;mut buf);</p>
<p>// symlink: parent -&gt; ..
        let mut header = Header::new_gnu();
        header.set_path("symlink")?;
        header.set_link_name("..")?;
        header.set_entry_type(EntryType::Symlink);
        header.set_size(0);
        header.set_cksum();
        builder.append(&amp;header, io::empty())?;</p>
<p>// file: symlink/exploit/foo/bar
        let mut header = Header::new_gnu();
        header.set_path("symlink/exploit/foo/bar")?;
        header.set_size(0);
        header.set_cksum();
        builder.append(&amp;header, io::empty())?;</p>
<p>builder.finish()?;
    };</p>
<p>Archive::new(&amp;*buf).unpack("demo")
}
```</p>
<p>This has been fixed in https://github.com/alexcrichton/tar-rs/pull/259 and is
published as `tar` 0.4.36. Thanks to Martin Michaelis ([@mgjm](https://github.com/mgjm)) for
discovering and reporting this, and Nikhil Benesch ([@benesch](https://github.com/benesch)) for
the fix!</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2021-0080"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-38511</id>
    <title>UBUNTU-CVE-2021-38511</title>
    <updated>2026-10-03T15:57:53.119615+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: rust-tar, Ubuntu:Pro:22.04:LTS: rust-tar, Ubuntu:24.04:LTS: rust-tar, Ubuntu:25.10: rust-tar, Ubuntu:26.04:LTS: rust-tar</p>
<p>An issue was discovered in the tar crate before 0.4.36 for Rust. When symlinks are present in a TAR archive, extraction can create arbitrary directories via .. traversal.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-38511"/>
  </entry>
</feed>
