[El-errata] ELSA-2026-61586-0 Moderate: Oracle Linux 10 tar security, bug fix, and enhancement update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Thu Sep 3 23:31:54 UTC 2026
Oracle Linux Security Advisory ELSA-2026-61586-0
http://linux.oracle.com/errata/ELSA-2026-61586-0.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
tar-1.35-13.el10_2.x86_64.rpm
aarch64:
tar-1.35-13.el10_2.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/tar-1.35-13.el10_2.src.rpm
Related CVEs:
CVE-2026-5704
CVE-2026-18477
CVE-2026-18508
Description of changes:
[2:1.35-13]
- Backport upstream patches for CVE-2026-18477, fixes a bug
where incremental restore with cyclic renames between backups
may create a temporary directory at an archive-controlled path
outside the extraction tree.
The fix for CVE-2025-45582 already prevents exploiting
this problem, so it is more a correctness and hardening change.
[2:1.35-12]
- Backport upstream fix for CVE-2026-5704 (file injection hidden from -t)
- Fix --one-top-level with absolute path (broken by the CVE-2025-45582 fix)
Also fixes CVE-2026-18508 (escape from --one-top-level via hardlinks).
- Upstream fix for build with libacl 2.4.0
More information about the El-errata
mailing list