Back Linuxsecurity Mageia Archive-Tar Critical Extraction Attacks Vulnerability 2026
Description: The updated package fixes security vulnerabilities: Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. (CVE-2026-42496) Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. (CVE-2026-42497) Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. (CVE-2026-9538)
Description: The updated package fixes security vulnerabilities: Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. (CVE-2026-42496) Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. (CVE-2026-42497) Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. (CVE-2026-9538)
- - - - - - -
-
-
-
-
-
-
-
- 9/core/perl-Archive-Tar-2.380.0-2.1.mga9
- 9/core/perl-Archive-Tar-2.380.0-2.1.mga9
Publication date: 24 Jun 2026 URL: https: //advisories.mageia.org/MGASA-2026-0230.html Type: security CVE: CVE-2026-42496, CVE-2026-42497, CVE-2026-9538
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
