Logo
vulnerabilityCVE-2026-5704
Name
CVE-2026-5704
Source
NVD ( link)Debian ( link)
Description
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
tar
Patched

Vulnerability Ratings#


5
CVSSv31
5.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.35
Not Affected
buildroot
master
1.35
Not Affected
openwrt
master
1.35-r1
Not Affected
openwrt
openwrt-25.12
1.35-r1
Not Affected
yocto
kirkstone
1.35
Not Affected
yocto
master
1.35
Patched

Resolved with patches#


tar (yocto:master)

#
Title
Author
Resolve
1
Fix more -t/-x discrepancies
Paul Eggert <eggert@cs.ucla.edu>
CVE-2026-5704
2
--no-overwrite-dir no overwrite even temporarily
Paul Eggert <eggert@cs.ucla.edu>
CVE-2026-5704
3
Handle directory members consistently when listing and when
Sergey Poznyakoff <gray@gnu.org>
CVE-2026-5704
4
Prefer other types to int in extract.c
Paul Eggert <eggert@cs.ucla.edu>
CVE-2026-5704

tar (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix more -t/-x discrepancies
Paul Eggert <eggert@cs.ucla.edu>
CVE-2026-5704
2
--no-overwrite-dir no overwrite even temporarily
Paul Eggert <eggert@cs.ucla.edu>
CVE-2026-5704
3
Handle directory members consistently when listing and when
Sergey Poznyakoff <gray@gnu.org>
CVE-2026-5704
4
Prefer other types to int in extract.c
Paul Eggert <eggert@cs.ucla.edu>
CVE-2026-5704