Your message dated Fri, 28 Aug 2026 19:19:12 +0000
with message-id <[email protected]>
and subject line Bug#1145200: fixed in golang-github-moby-go-archive 0.3.3-1
has caused the Debian Bug report #1145200,
regarding golang-github-moby-go-archive: CVE-2026-17106
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1145200: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1145200
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: golang-github-moby-go-archive
Version: 0.2.0-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for golang-github-moby-go-archive.
CVE-2026-17106[0]:
| The tar extraction routines in moby/go-archive (Unpack, UnpackLayer,
| Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine
| filesystem operations to the destination directory. The extractor
| decides where each archive entry lands using lexical string checks
| and then performs the filesystem operation on a path that is
| resolved by the OS, so links introduced by the archive can be
| followed out of the destination directory. An attacker who controls
| the contents of an archive can create or overwrite files at
| arbitrary paths writable by the extracting process.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-17106
https://www.cve.org/CVERecord?id=CVE-2026-17106
[1] https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: golang-github-moby-go-archive
Source-Version: 0.3.3-1
Done: Mathias Gibbens <[email protected]>
We believe that the bug you reported is fixed in the latest version of
golang-github-moby-go-archive, which is due to be installed in the Debian FTP
archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Mathias Gibbens <[email protected]> (supplier of updated
golang-github-moby-go-archive package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 28 Aug 2026 14:07:41 +0000
Source: golang-github-moby-go-archive
Architecture: source
Version: 0.3.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <[email protected]>
Changed-By: Mathias Gibbens <[email protected]>
Closes: 1145200
Changes:
golang-github-moby-go-archive (0.3.3-1) unstable; urgency=medium
.
* New upstream release
- Includes fix for CVE-2026-17106 (Closes: #1145200)
* Update Standards-Version to 4.7.4 in d/control (no changes needed)
Checksums-Sha1:
3394e8a58c945117d537d3b1b5b1b684d850bf6b 2491
golang-github-moby-go-archive_0.3.3-1.dsc
ae1118902b3edb3fd92c0c8d2f43f91070cb588d 98546
golang-github-moby-go-archive_0.3.3.orig.tar.gz
a7d24c41eeb583b07b2e4874b2eca20a4d5a0889 3140
golang-github-moby-go-archive_0.3.3-1.debian.tar.xz
c53a952c871bac489060cd11af00b954e54646b0 6438
golang-github-moby-go-archive_0.3.3-1_amd64.buildinfo
Checksums-Sha256:
a852b795b45d8d55161f7fc2c642ac7262408bfd8aeef85bdb0767c08b56db99 2491
golang-github-moby-go-archive_0.3.3-1.dsc
0b2669026ee52a9ddfafd6189c0886892af7ccf3e4e6f0eed7eaf56109accdc1 98546
golang-github-moby-go-archive_0.3.3.orig.tar.gz
d6c764b058a82040dbc0f48ff18323f4a275ac319ae1adc01ab382351b6e5669 3140
golang-github-moby-go-archive_0.3.3-1.debian.tar.xz
a92a870b6d9a897e5674e9cbe57094e2980d8c6f73f9ad6eb3c43abdf9b926e4 6438
golang-github-moby-go-archive_0.3.3-1_amd64.buildinfo
Files:
b354b693e019641de45373764cf9ba55 2491 golang optional
golang-github-moby-go-archive_0.3.3-1.dsc
c3e8c80aec4fc8933416e4127a5e0a7a 98546 golang optional
golang-github-moby-go-archive_0.3.3.orig.tar.gz
a41b7ba50e66c37181cc43986f5427d4 3140 golang optional
golang-github-moby-go-archive_0.3.3-1.debian.tar.xz
ddac25d7fe1fd25bef97aa39fd580cdb 6438 golang optional
golang-github-moby-go-archive_0.3.3-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJGBAEBCgAwFiEE1Bp60H32xfynSJ8cKe7i1uz0QvkFAmqR26gSHGdpYm1hdEBk
ZWJpYW4ub3JnAAoJECnu4tbs9EL5lN8QAJkP+yVT1h85uWlbFQD/SCFw6LyIH1mA
w7JUi6sfsvOA0dNfUZP/PCy6AVxN1c9Z+zZVMVV4FE9shi+JypZx/1vO78il7qEr
ZDh4zt2NMFrhYX1hKdlmLxsqFlt8u9Q1QeMloHE+F4J6tC5wrHo5hnzC29YbQNq+
WllkTHlEm3mWWdnaz0/3M78OLY07kdvxpNwTsNPHSuxPM/mRrvtnK9+4foKd+fWw
VQnaXTLG4FtiFxvz9AmTLUIllbQozc/E3GjBmVOOaKvajvGyLtJiC3OAJuCKBaYZ
DN/J4jDDWvU5A9sXapJCWE/JTyzkquNOeHFKpArvw3s+Esw3LLl+ERlKwDXrJhV5
MhpyfZzRp/i5ezvuhGzYIEGXE6BQfBipAkdkGiEeRf3gyZvw5hmBzIXH2vdX8F5k
c1EbyQolTGC37XLynUXGkI5KUmXjIS26n6b3mKfX+GVAw+mU5NqxCTCZ+I23JyZr
Hn2QvC8SLPc2MZaJL83mPtyM0guZIaRLxs7L4CyaDbmRcvhbp/F2MWw6FIV/wE3x
fNIEb70J83uTa2UWg51rJ6tUSMDydZAntz0BMZQyqzzQSAR0I8XIaJUrpZ4WvlIU
usV5IXR82kdIczln8dBCziIVOzGZV4c6zzQUBcqP2qH0kx5jOwjZeTzb95MyIw4O
YEV7aw6Z7Cyi
=6FmU
-----END PGP SIGNATURE-----
pgp3cRMGeWpEQ.pgp
Description: PGP signature
--- End Message ---