CVE-2026-5704 Details
Description
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.
A vulnerability in GNU Tar allows remote attackers to inject hidden files with malicious content by crafting a specific archive. This exploitation bypasses pre-extraction inspection methods, potentially leading to undetected introduction of harmful files onto a system. The issue arises from the handling of non-data-bearing typeflags in the archive, which can be manipulated to create discrepancies between the archive's listed contents and the files actually extracted.
Avoid extracting tar archives from untrusted sources. If it is necessary to process untrusted archives, do so in a sandboxed environment to minimize potential risks.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/04/11/10 | CVE | ExploitMailing ListThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/04/11/11 | CVE | Mailing ListThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/04/12/2 | CVE | ExploitMailing ListThird Party Advisory |
| https://access.redhat.com/errata/RHSA-2026:61581 | [email protected] | |
| https://access.redhat.com/errata/RHSA-2026:61586 | [email protected] | |
| https://access.redhat.com/errata/RHSA-2026:61783 | [email protected] | |
| https://access.redhat.com/errata/RHSA-2026:66018 | [email protected] | |
| https://access.redhat.com/errata/RHSA-2026:66514 | [email protected] | |
| https://access.redhat.com/errata/RHSA-2026:70390 | [email protected] | |
| https://access.redhat.com/security/cve/CVE-2026-5704 | [email protected] | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2455360 | [email protected] | ExploitIssue TrackingThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gnu tar | All versions |
CPE
Remediation
| |
| redhat hardened images | All versions |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | CVE Modified | [email protected] |
| Sep 10, 2026 | CVE Modified | [email protected] |
| Sep 10, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | CVE |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | Initial Analysis | [email protected] |
| Apr 12, 2026 | CVE Modified | CVE |
| Apr 12, 2026 | CVE Modified | CVE |
| Apr 11, 2026 | CVE Modified | CVE |
| Apr 6, 2026 | New CVE Received | [email protected] |