CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GNU Tar — security advisories

vendor: GNU1 advisories1 sourcelatest 2026-08-06⚡ RSS feed

Every advisory CSIRTS.com has correlated to GNU Tar, newest first — across national CERTs, vendor PSIRTs and vulnerability databases.

⚡ Watch GNU Tar

Get an email when a new GNU Tar advisory drops — max one per day, one-click unsubscribe.

CVE-2025-45582: GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This b

mediumCVSS 4.1CVE-2025-45582msrc2026-08-06