Advisories ยป MGASA-2026-0230

Updated perl-Archive-Tar package fixes security vulnerabilities

Publication date: 24 Jun 2026
Modification date: 24 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-42496 , CVE-2026-42497 , CVE-2026-9538

Description

The updated package fixes security vulnerabilities:
Archive::Tar versions before 3.08 for Perl extract symlinks with
attacker controlled targets outside the extraction directory.
(CVE-2026-42496)
Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker
controlled paths outside the extraction directory. (CVE-2026-42497)
Archive::Tar versions before 3.10 for Perl allow memory exhaustion via
attacker controlled entry size field in tar header. (CVE-2026-9538)
                

References

SRPMS

9/core