RHSA-2026:0067MediumCVSS 5.6
Red Hat Security Advisory: tar security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-45582 — tar: Tar path traversal
🎯 Affected products14
- Red Hat Enterprise Linux BaseOS (v. 9)
- tar-2:1.34-9.el9_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- tar-2:1.34-9.el9_7.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- tar-2:1.34-9.el9_7.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- tar-2:1.34-9.el9_7.src as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- tar-2:1.34-9.el9_7.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- tar-debuginfo-2:1.34-9.el9_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- tar-debuginfo-2:1.34-9.el9_7.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- tar-debuginfo-2:1.34-9.el9_7.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- tar-debuginfo-2:1.34-9.el9_7.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- tar-debugsource-2:1.34-9.el9_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- tar-debugsource-2:1.34-9.el9_7.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- tar-debugsource-2:1.34-9.el9_7.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- tar-debugsource-2:1.34-9.el9_7.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Untrusted TAR archives should always be extracted in an empty directory. When multiple untrusted archives need to be extracted, the same directory must not be re-used without removing all content extracted form the previous archive before extracting the next archive.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:0067
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2379592
- externalhttps://issues.redhat.com/browse/RHEL-136277
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_0067.json