[El-errata] ELSA-2026-70390 Moderate: Oracle Linux 8 tar security, bug fix, and enhancement update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Thu Sep 24 10:18:02 UTC 2026


Oracle Linux Security Advisory ELSA-2026-70390

http://linux.oracle.com/errata/ELSA-2026-70390.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
tar-1.30-13.el8_10.x86_64.rpm

aarch64:
tar-1.30-13.el8_10.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/tar-1.30-13.el8_10.src.rpm

Related CVEs:

CVE-2025-45582
CVE-2026-5704
CVE-2026-18477
CVE-2026-18508




Description of changes:

[2:1.30-13]
- Backport upstream fix for CVE-2026-5704 (file injection hidden from -t)
- Fix --one-top-level with absolute path (broken by the CVE-2025-45582 fix)
  Also fixes CVE-2026-18508 (escape from --one-top-level via hardlinks).
- Upstream fix for build with libacl 2.4.0
- Backport upstream patches for CVE-2026-18477, fixes a bug
  where incremental restore with cyclic renames between backups
  may create a temporary directory at an archive-controlled path
  outside the extraction tree.
  The fix for CVE-2025-45582 already prevents exploiting
  this problem, so it is more a correctness and hardening change.

[2:1.30-12]
- Backport upstream changes to jailify extraction directory
  Includes related gnulib changes to add openat2
  Fixes CVE-2025-45582




More information about the El-errata mailing list