RHSA-2026:0435MediumCVSS 5.6
Red Hat Security Advisory: tar security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-45582 — tar: Tar path traversal
🎯 Affected products14
- Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- tar-2:1.34-7.el9_6.2.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- tar-2:1.34-7.el9_6.2.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- tar-2:1.34-7.el9_6.2.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- tar-2:1.34-7.el9_6.2.src as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- tar-2:1.34-7.el9_6.2.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- tar-debuginfo-2:1.34-7.el9_6.2.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- tar-debuginfo-2:1.34-7.el9_6.2.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- tar-debuginfo-2:1.34-7.el9_6.2.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- tar-debuginfo-2:1.34-7.el9_6.2.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- tar-debugsource-2:1.34-7.el9_6.2.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- tar-debugsource-2:1.34-7.el9_6.2.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- tar-debugsource-2:1.34-7.el9_6.2.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
- tar-debugsource-2:1.34-7.el9_6.2.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.6)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Untrusted TAR archives should always be extracted in an empty directory. When multiple untrusted archives need to be extracted, the same directory must not be re-used without removing all content extracted form the previous archive before extracting the next archive.