[Pkg-rust-maintainers] Bug#1144402: rust-tar: CVE-2026-70622
Salvatore Bonaccorso
carnil at debian.org
Fri Aug 14 16:38:53 BST 2026
Source: rust-tar
Version: 0.4.45-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Hi,
The following vulnerability was published for rust-tar.
At point of writing there was only the gist at [1], can you check with
upstream if this is known/reported/fixed?
CVE-2026-70622[0]:
| tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape
| vulnerability in the Builder::append_dir_all() function that allows
| attackers to read files outside the intended source root directory
| by planting symlinks in an attacker-controlled directory. When a
| privileged process archives an untrusted directory, the function
| follows symlinks without verifying that resolved targets remain
| within the source root, causing out-of-bounds files to be included
| in the archive as regular files and disclosed to the attacker.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-70622
https://www.cve.org/CVERecord?id=CVE-2026-70622
[1] https://gist.github.com/thesmartshadow/e7dac0bb690ee17b9cc142154cb11726
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
More information about the Pkg-rust-maintainers
mailing list