The GNU tar program can save multiple files in an archive and restore files from an archive.
Security Fix(es):
tar: tar: Hidden file injection via crafted archives (CVE-2026-5704)
tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape (CVE-2026-18477)
tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite (CVE-2026-18508)
Bug Fix(es) and Enhancement(s):
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
{
"license": "CC-BY-4.0",
"source_advisory": "RHSA-2026:61581",
"license_url": "https://creativecommons.org/licenses/by/4.0/"
}