This bug was fixed in the package tar - 1.35+dfsg-5ubuntu1
---------------
tar (1.35+dfsg-5ubuntu1) stonking; urgency=medium
* Merge with Debian unstable. (LP: #2163533) Remaining changes:
- d/patches:
+ SECURITY UPDATE: File overwrite via directory traversal
- debian/patches/CVE-2025-45582-*.patch: Backport openat2 support in
order
to jailify the extraction directory.
- Addresses CVE-2025-45582
+ SECURITY UPDATE: file injection via crafted archive
- debian/patches/CVE-2026-5704.patch: always call skip_member() after
extraction in src/extract.c, fix skim_member() to skip directory data
in src/list.c, remove conditional skip_member() call from
purge_directory in src/incremen.c
- debian/patches/CVE-2026-5704-*.patch: address a regression that makes
valid files not extract in src/list.c, tests/Makefile.am,
tests/extrac32.at, tests/extrac34.at, test/testsuite.at,
src/extract.c,
tests/extract23, tests/extrac30.at.
- debian/patches/CVE-2026-5704-5.patch: fix "Old archives with nonzero
directory sizes failing to be extracted" by forcing the size to zero
afor DIRTYPE in read_header() in src/list.c
- Addresses CVE-2026-5704
* New changes:
- d/patches:
+ Fix d/p/0001 line markers
-- Pierre-Elliott Bécue <[email protected]> Tue, 18
Aug 2026 19:58:00 +0200
** Changed in: tar (Ubuntu)
Status: Triaged => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2025-45582
** CVE added: https://cve.org/CVERecord?id=CVE-2026-5704
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163533
Title:
Merge tar 1.35+dfsg-5 from Debian for stonking cycle
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/tar/+bug/2163533/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs