ELSA-2026-61581-0

ELSA-2026-61581-0 - tar security, bug fix, and enhancement update

Type:SECURITY
Impact:MODERATE
Release Date:2026-09-01

Description


[2:1.34-13]
- Backport upstream patches for CVE-2026-18477, fixes a bug
where incremental restore with cyclic renames between backups
may create a temporary directory at an archive-controlled path
outside the extraction tree.
The fix for CVE-2025-45582 already prevents exploiting
this problem, so it is more a correctness and hardening change.

[2:1.34-12]
- Backport upstream fix for CVE-2026-5704 (file injection hidden from -t)
- Fix --one-top-level with absolute path (broken by the CVE-2025-45582 fix)
Also fixes CVE-2026-18508 (escape from --one-top-level via hardlinks).
- Upstream fix for build with libacl 2.4.0


Related CVEs


CVE-2026-18477
CVE-2026-18508
CVE-2026-5704

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) tar-1.34-13.el9_8.src.rpm8ae7ad27cf95f207be7e69325a34370f0740bfdca0d7fc8f2baedd5e4abb3a56-ol9_aarch64_baseos_latest
tar-1.34-13.el9_8.src.rpm8ae7ad27cf95f207be7e69325a34370f0740bfdca0d7fc8f2baedd5e4abb3a56-ol9_aarch64_u8_baseos_patch
tar-1.34-13.el9_8.aarch64.rpm88ff59a8f554aa1d575465c511420f5b6368468b16f3bc5bec4a5257c7d95ffd-ol9_aarch64_baseos_latest
tar-1.34-13.el9_8.aarch64.rpm88ff59a8f554aa1d575465c511420f5b6368468b16f3bc5bec4a5257c7d95ffd-ol9_aarch64_u8_baseos_patch
Oracle Linux 9 (x86_64) tar-1.34-13.el9_8.src.rpm8ae7ad27cf95f207be7e69325a34370f0740bfdca0d7fc8f2baedd5e4abb3a56-ol9_x86_64_baseos_latest
tar-1.34-13.el9_8.src.rpm8ae7ad27cf95f207be7e69325a34370f0740bfdca0d7fc8f2baedd5e4abb3a56-ol9_x86_64_u8_baseos_patch
tar-1.34-13.el9_8.x86_64.rpmfa16daaf8f842641ee9a019ea419d19f4d039d01dabca114e24733f506d5a166-ol9_x86_64_baseos_latest
tar-1.34-13.el9_8.x86_64.rpmfa16daaf8f842641ee9a019ea419d19f4d039d01dabca114e24733f506d5a166-ol9_x86_64_u8_baseos_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete