Linuxsecurity Critical Vulnerability in Tar Utility Allows File Overwrites
Article Content
Browse articles
- •A critical vulnerability in tar allows file overwrites via symlink mishandling.
- •Affected Ubuntu versions include 26.04, 24.04, and 22.04 LTS.
- •Users are urged to update their systems to prevent potential exploitation.
A vulnerability in the tar utility was discovered, affecting multiple Ubuntu versions. The issue arises from incorrect handling of symlinks during archive extraction, potentially allowing attackers to overwrite arbitrary files. This vulnerability is identified as USN-8510-1 and is associated with CVE-2025. Affected versions include Ubuntu 26.04 LTS, 24.04 LTS, and 22.04 LTS. Users are advised to update their systems to mitigate the risk. The vulnerability poses a significant threat to system integrity if exploited. Ubuntu Pro offers ten-year security coverage for affected packages. The vulnerability was disclosed on July 6, 2026, and is critical for users of the tar utility.
Ask AI about this cluster
Answers cite the sources they use
Updated 95d ago How this analysis works
Timeline
2026-07-06
Vulnerability USN-8510-1 disclosed
A critical vulnerability in the tar utility was announced, affecting multiple Ubuntu versions due to symlink mishandling.
Ubuntu2026-07-06
CVE-2025 associated with tar vulnerability
The vulnerability allows attackers to overwrite arbitrary files when extracting archives, posing a significant risk.
LinuxsecurityMore articles in this cluster (7)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…