[El-errata] ELSA-2026-61586-0 Moderate: Oracle Linux 10 tar security, bug fix, and enhancement update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Thu Sep 3 23:31:54 UTC 2026


Oracle Linux Security Advisory ELSA-2026-61586-0

http://linux.oracle.com/errata/ELSA-2026-61586-0.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
tar-1.35-13.el10_2.x86_64.rpm

aarch64:
tar-1.35-13.el10_2.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/tar-1.35-13.el10_2.src.rpm

Related CVEs:

CVE-2026-5704
CVE-2026-18477
CVE-2026-18508




Description of changes:

[2:1.35-13]
- Backport upstream patches for CVE-2026-18477, fixes a bug
  where incremental restore with cyclic renames between backups
  may create a temporary directory at an archive-controlled path
  outside the extraction tree.
  The fix for CVE-2025-45582 already prevents exploiting
  this problem, so it is more a correctness and hardening change.

[2:1.35-12]
- Backport upstream fix for CVE-2026-5704 (file injection hidden from -t)
- Fix --one-top-level with absolute path (broken by the CVE-2025-45582 fix)
  Also fixes CVE-2026-18508 (escape from --one-top-level via hardlinks).
- Upstream fix for build with libacl 2.4.0




More information about the El-errata mailing list