<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:36:48 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:61581 — Moderate: tar security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:61581</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: tar&lt;/p&gt;
&lt;p&gt;The GNU tar program can save multiple files in an archive and restore files from an archive.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tar: tar: Hidden file injection via crafted archives (CVE-2026-5704)
  * tar: tar: TOCTOU in incremental dumpdir &amp;#39;X&amp;#39; rename handling allows restore path escape (CVE-2026-18477)
  * tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite (CVE-2026-18508)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* tar: --one-top-level with absolute path fails [almalinux-9] (JIRA:AlmaLinux-144021)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: tar&lt;/p&gt;
&lt;p&gt;The GNU tar program can save multiple files in an archive and restore files from an archive.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tar: tar: Hidden file injection via crafted archives (CVE-2026-5704)
  * tar: tar: TOCTOU in incremental dumpdir &amp;#39;X&amp;#39; rename handling allows restore path escape (CVE-2026-18477)
  * tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite (CVE-2026-18508)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* tar: --one-top-level with absolute path fails [almalinux-9] (JIRA:AlmaLinux-144021)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:61581</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1249 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249</link>
      <description>certfr-2026-avi-1249</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249</guid>
    </item>
    <item>
      <title>EUVD-2026-373901</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-373901</link>
      <description>EUVD-2026-373901</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-373901</guid>
    </item>
    <item>
      <title>fkie_cve-2026-5704</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-5704</link>
      <description>&lt;p&gt;A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-5704</guid>
    </item>
    <item>
      <title>GHSA-jqqw-37x4-9rwj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jqqw-37x4-9rwj</link>
      <description>&lt;p&gt;A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jqqw-37x4-9rwj</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-5704 — Tar: tar: hidden file injection via crafted archives</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-5704</link>
      <description>msrc_CVE-2026-5704</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-5704</guid>
    </item>
    <item>
      <title>OESA-2026-3223 — tar security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3223</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: tar, openEuler:24.03-LTS-SP3: tar, openEuler:24.03-LTS-SP4: tar, openEuler:20.03-LTS-SP4: tar, openEuler:22.03-LTS-SP4: tar&lt;/p&gt;
&lt;p&gt;GNU Tar provides the ability to create tar archives, as well as various other kinds of manipulation. For example, you can use Tar on previously created archives to extract files, to store additional files, or to update or list files which were already stored.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.(CVE-2026-5704)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: tar, openEuler:24.03-LTS-SP3: tar, openEuler:24.03-LTS-SP4: tar, openEuler:20.03-LTS-SP4: tar, openEuler:22.03-LTS-SP4: tar&lt;/p&gt;
&lt;p&gt;GNU Tar provides the ability to create tar archives, as well as various other kinds of manipulation. For example, you can use Tar on previously created archives to extract files, to store additional files, or to update or list files which were already stored.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.(CVE-2026-5704)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3223</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11125-1 — tar-1.35-8.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11125-1</link>
      <description>&lt;p&gt;tar-1.35-8.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tar-1.35-8.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11125-1</guid>
    </item>
    <item>
      <title>RHSA-2026:61783 — Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:61783</link>
      <description>&lt;p&gt;webpack-dev-middleware: lack of URL validation may lead to file leak curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect tar: tar: Hidden file injection via crafted archives fast-uri: fast-uri: URI authority bypass due to improper delimiter handling libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free curl: curl: Insecure connection establishment due to TLS configuration mismatch curl: curl: Man-in-the-middle attack via SSH host key bypass sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering tar: tar: TOCTOU in incremental dumpdir &amp;#39;X&amp;#39; rename handling allows restore path escape tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility gzip: gzip: Information disclosure via global buffer overflow in LZH decompression python-idna: idna: Denial of Service via…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;webpack-dev-middleware: lack of URL validation may lead to file leak curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect tar: tar: Hidden file injection via crafted archives fast-uri: fast-uri: URI authority bypass due to improper delimiter handling libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free curl: curl: Insecure connection establishment due to TLS configuration mismatch curl: curl: Man-in-the-middle attack via SSH host key bypass sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering tar: tar: TOCTOU in incremental dumpdir &amp;#39;X&amp;#39; rename handling allows restore path escape tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility gzip: gzip: Information disclosure via global buffer overflow in LZH decompression python-idna: idna: Denial of Service via…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:61783</guid>
    </item>
    <item>
      <title>RLSA-2026:61581 — Moderate: tar security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:61581</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: tar&lt;/p&gt;
&lt;p&gt;The GNU tar program can save multiple files in an archive and restore files from an archive.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tar: tar: Hidden file injection via crafted archives (CVE-2026-5704)&lt;/p&gt;
&lt;p&gt;* tar: tar: TOCTOU in incremental dumpdir &amp;#39;X&amp;#39; rename handling allows restore path escape (CVE-2026-18477)&lt;/p&gt;
&lt;p&gt;* tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite (CVE-2026-18508)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* tar: --one-top-level with absolute path fails [rhel-9] (JIRA:Rocky Linux-144021)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: tar&lt;/p&gt;
&lt;p&gt;The GNU tar program can save multiple files in an archive and restore files from an archive.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tar: tar: Hidden file injection via crafted archives (CVE-2026-5704)&lt;/p&gt;
&lt;p&gt;* tar: tar: TOCTOU in incremental dumpdir &amp;#39;X&amp;#39; rename handling allows restore path escape (CVE-2026-18477)&lt;/p&gt;
&lt;p&gt;* tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite (CVE-2026-18508)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* tar: --one-top-level with absolute path fails [rhel-9] (JIRA:Rocky Linux-144021)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:61581</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22289-1 — Security update for tar</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22289-1</link>
      <description>&lt;p&gt;Security update for tar&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tar&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22289-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-5704</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-5704</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tar, Ubuntu:Pro:16.04:LTS: tar, Ubuntu:Pro:18.04:LTS: tar, Ubuntu:Pro:20.04:LTS: tar, Ubuntu:22.04:LTS: tar, Ubuntu:24.04:LTS: tar, Ubuntu:25.10: tar, Ubuntu:26.04:LTS: tar&lt;/p&gt;
&lt;p&gt;A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tar, Ubuntu:Pro:16.04:LTS: tar, Ubuntu:Pro:18.04:LTS: tar, Ubuntu:Pro:20.04:LTS: tar, Ubuntu:22.04:LTS: tar, Ubuntu:24.04:LTS: tar, Ubuntu:25.10: tar, Ubuntu:26.04:LTS: tar&lt;/p&gt;
&lt;p&gt;A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-5704</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1057 — GNU tar: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1057</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in GNU tar ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in GNU tar ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1057</guid>
    </item>
  </channel>
</rss>
