Skip to content
Mageia Archive-Tar Critical Extraction Attacks Vulnerability 2026

Mageia Archive-Tar Critical Extraction Attacks Vulnerability 2026

Linuxsecurity LinuxSecurity Advisories June 24, 2026

Description: The updated package fixes security vulnerabilities: Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. (CVE-2026-42496) Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. (CVE-2026-42497) Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. (CVE-2026-9538)

Description: The updated package fixes security vulnerabilities: Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. (CVE-2026-42496) Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. (CVE-2026-42497) Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. (CVE-2026-9538)

- - - - - - -

-

-

-

-

-

-

-

- 9/core/perl-Archive-Tar-2.380.0-2.1.mga9

- 9/core/perl-Archive-Tar-2.380.0-2.1.mga9

Publication date: 24 Jun 2026 URL: https: //advisories.mageia.org/MGASA-2026-0230.html Type: security CVE: CVE-2026-42496, CVE-2026-42497, CVE-2026-9538

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities