This bug was fixed in the package tar - 1.35+dfsg-5ubuntu1

---------------
tar (1.35+dfsg-5ubuntu1) stonking; urgency=medium

  * Merge with Debian unstable. (LP: #2163533) Remaining changes:
    - d/patches:
      + SECURITY UPDATE: File overwrite via directory traversal
        - debian/patches/CVE-2025-45582-*.patch: Backport openat2 support in 
order
        to jailify the extraction directory.
        - Addresses CVE-2025-45582
      + SECURITY UPDATE: file injection via crafted archive
        - debian/patches/CVE-2026-5704.patch: always call skip_member() after
          extraction in src/extract.c, fix skim_member() to skip directory data
          in src/list.c, remove conditional skip_member() call from
          purge_directory in src/incremen.c
        - debian/patches/CVE-2026-5704-*.patch: address a regression that makes
          valid files not extract in src/list.c, tests/Makefile.am,
          tests/extrac32.at, tests/extrac34.at, test/testsuite.at, 
src/extract.c,
          tests/extract23, tests/extrac30.at.
        - debian/patches/CVE-2026-5704-5.patch: fix "Old archives with nonzero
          directory sizes failing to be extracted" by forcing the size to zero
          afor DIRTYPE in read_header() in src/list.c
        - Addresses CVE-2026-5704
  * New changes:
    - d/patches:
      + Fix d/p/0001 line markers

 -- Pierre-Elliott Bécue <[email protected]>  Tue, 18
Aug 2026 19:58:00 +0200

** Changed in: tar (Ubuntu)
       Status: Triaged => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2025-45582

** CVE added: https://cve.org/CVERecord?id=CVE-2026-5704

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163533

Title:
  Merge tar 1.35+dfsg-5 from Debian for stonking cycle

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/tar/+bug/2163533/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to