ELSA-2026-61586-0

ELSA-2026-61586-0 - tar security, bug fix, and enhancement update

Type:SECURITY
Impact:MODERATE
Release Date:2026-09-01

Description


[2:1.35-13]
- Backport upstream patches for CVE-2026-18477, fixes a bug
where incremental restore with cyclic renames between backups
may create a temporary directory at an archive-controlled path
outside the extraction tree.
The fix for CVE-2025-45582 already prevents exploiting
this problem, so it is more a correctness and hardening change.

[2:1.35-12]
- Backport upstream fix for CVE-2026-5704 (file injection hidden from -t)
- Fix --one-top-level with absolute path (broken by the CVE-2025-45582 fix)
Also fixes CVE-2026-18508 (escape from --one-top-level via hardlinks).
- Upstream fix for build with libacl 2.4.0


Related CVEs


CVE-2026-18477
CVE-2026-18508
CVE-2026-5704

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 10 (aarch64) tar-1.35-13.el10_2.src.rpmcf27f52883af4cbd9188151541702012a00e5b8a63524ff2abb87bc297673273-ol10_aarch64_baseos_latest
tar-1.35-13.el10_2.src.rpmcf27f52883af4cbd9188151541702012a00e5b8a63524ff2abb87bc297673273-ol10_aarch64_u2_baseos_patch
tar-1.35-13.el10_2.aarch64.rpmf35c7b1671d978b245ffffd898423c9392b9721d4bb340308a00855387c86fd5-ol10_aarch64_baseos_latest
tar-1.35-13.el10_2.aarch64.rpmf35c7b1671d978b245ffffd898423c9392b9721d4bb340308a00855387c86fd5-ol10_aarch64_u2_baseos_patch
Oracle Linux 10 (x86_64) tar-1.35-13.el10_2.src.rpmcf27f52883af4cbd9188151541702012a00e5b8a63524ff2abb87bc297673273-ol10_x86_64_baseos_latest
tar-1.35-13.el10_2.src.rpmcf27f52883af4cbd9188151541702012a00e5b8a63524ff2abb87bc297673273-ol10_x86_64_u2_baseos_patch
tar-1.35-13.el10_2.x86_64.rpm4a15ccd44bda65772547dbc4dfef9d36bf0d335e60442e60d2dd14d1407906d1-ol10_x86_64_baseos_latest
tar-1.35-13.el10_2.x86_64.rpm4a15ccd44bda65772547dbc4dfef9d36bf0d335e60442e60d2dd14d1407906d1-ol10_x86_64_u2_baseos_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete