[CLSA-2026:1787337920] tar: Fix of CVE-2026-18477
Type:
security
Severity:
Moderate
Release date:
2026-08-21 18:45:31 UTC
Description:
- CVE-2026-18477: apply safer_name_suffix to incremental dumpdir 'X' entries so the temporary directory template can no longer escape the extraction directory - use mkdtempat instead of mkdtemp so the 'X' temporary directory is created relative to -C (backport of upstream d479b2cc)
CVEs fixed:
Updated packages:
  • tar-1.34-7.el9.tuxcare.els4.x86_64.rpm
    sha:beb95dc26c055dbacc09280e67156a464375a813848538b0b5afbe864c664504
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.