<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:40:47.828470+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:61581</id>
    <title>ALSA-2026:61581 — Moderate: tar security, bug fix, and enhancement update</title>
    <updated>2026-10-03T02:40:47.991439+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: tar</p>
<p>The GNU tar program can save multiple files in an archive and restore files from an archive.</p>
<p>Security Fix(es):</p>
<p>* tar: tar: Hidden file injection via crafted archives (CVE-2026-5704)
  * tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape (CVE-2026-18477)
  * tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite (CVE-2026-18508)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* tar: --one-top-level with absolute path fails [almalinux-9] (JIRA:AlmaLinux-144021)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:61581"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249</id>
    <title>certfr-2026-avi-1249 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T02:40:47.991507+00:00</updated>
    <content>certfr-2026-avi-1249</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-373901</id>
    <title>EUVD-2026-373901</title>
    <updated>2026-10-03T02:40:47.991527+00:00</updated>
    <content>EUVD-2026-373901</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-373901"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-5704</id>
    <title>fkie_cve-2026-5704</title>
    <updated>2026-10-03T02:40:47.991540+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-5704"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jqqw-37x4-9rwj</id>
    <title>GHSA-jqqw-37x4-9rwj</title>
    <updated>2026-10-03T02:40:47.991564+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jqqw-37x4-9rwj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-5704</id>
    <title>msrc_CVE-2026-5704 — Tar: tar: hidden file injection via crafted archives</title>
    <updated>2026-10-03T02:40:47.991579+00:00</updated>
    <content>msrc_CVE-2026-5704</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-5704"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3223</id>
    <title>OESA-2026-3223 — tar security update</title>
    <updated>2026-10-03T02:40:47.991595+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: tar, openEuler:24.03-LTS-SP3: tar, openEuler:24.03-LTS-SP4: tar, openEuler:20.03-LTS-SP4: tar, openEuler:22.03-LTS-SP4: tar</p>
<p>GNU Tar provides the ability to create tar archives, as well as various other kinds of manipulation. For example, you can use Tar on previously created archives to extract files, to store additional files, or to update or list files which were already stored.

Security Fix(es):</p>
<p>A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.(CVE-2026-5704)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3223"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11125-1</id>
    <title>openSUSE-SU-2026:11125-1 — tar-1.35-8.1 on GA media</title>
    <updated>2026-10-03T02:40:47.991626+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tar-1.35-8.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11125-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:61783</id>
    <title>RHSA-2026:61783 — Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage</title>
    <updated>2026-10-03T02:40:47.991642+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>webpack-dev-middleware: lack of URL validation may lead to file leak curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect tar: tar: Hidden file injection via crafted archives fast-uri: fast-uri: URI authority bypass due to improper delimiter handling libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free curl: curl: Insecure connection establishment due to TLS configuration mismatch curl: curl: Man-in-the-middle attack via SSH host key bypass sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility gzip: gzip: Information disclosure via global buffer overflow in LZH decompression python-idna: idna: Denial of Service via…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:61783"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:61581</id>
    <title>RLSA-2026:61581 — Moderate: tar security, bug fix, and enhancement update</title>
    <updated>2026-10-03T02:40:47.991731+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: tar</p>
<p>The GNU tar program can save multiple files in an archive and restore files from an archive.</p>
<p>Security Fix(es):</p>
<p>* tar: tar: Hidden file injection via crafted archives (CVE-2026-5704)</p>
<p>* tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape (CVE-2026-18477)</p>
<p>* tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite (CVE-2026-18508)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* tar: --one-top-level with absolute path fails [rhel-9] (JIRA:Rocky Linux-144021)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:61581"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22289-1</id>
    <title>SUSE-SU-2026:22289-1 — Security update for tar</title>
    <updated>2026-10-03T02:40:47.991759+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tar</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22289-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-5704</id>
    <title>UBUNTU-CVE-2026-5704</title>
    <updated>2026-10-03T02:40:47.991774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: tar, Ubuntu:Pro:16.04:LTS: tar, Ubuntu:Pro:18.04:LTS: tar, Ubuntu:Pro:20.04:LTS: tar, Ubuntu:22.04:LTS: tar, Ubuntu:24.04:LTS: tar, Ubuntu:25.10: tar, Ubuntu:26.04:LTS: tar</p>
<p>A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-5704"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1057</id>
    <title>WID-SEC-W-2026-1057 — GNU tar: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T02:40:47.991802+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in GNU tar ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1057"/>
  </entry>
</feed>
