Updated tar packages fix security vulnerabilities
Publication date: 14 Sep 2026Modification date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-45582 , CVE-2026-18508 , CVE-2026-18477
Description
GNU Tar through 1.35 allows file overwrite via directory traversal in
crafted TAR archives, with a certain two-step process. (CVE-2025-45582)
Tar: toctou in incremental dumpdir 'x' rename handling allows restore
path escape. (CVE-2026-18477)
Tar: --one-top-level hardlink targets not confined to top-level
directory enabling arbitrary file overwrite. (CVE-2026-18508)
References
- https://bugs.mageia.org/show_bug.cgi?id=36289
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ASLMG5TUYWS2IEKBCOWN5KZ2K55V366N/
- https://www.cve.org/CVERecord?id=CVE-2025-45582
- https://www.cve.org/CVERecord?id=CVE-2026-18508
- https://www.cve.org/CVERecord?id=CVE-2026-18477
SRPMS
10/core
- tar-1.35-4.1.mga10
9/core
- tar-1.35-4.1.mga9