-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 30 Apr 2026 04:21:06 +0200 Source: node-tar Architecture: source Version: 6.1.13+~cs7.0.5-1+deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org> Changed-By: Daniel Leidert <dleidert@debian.org> Changes: node-tar (6.1.13+~cs7.0.5-1+deb12u1) bookworm-security; urgency=medium . * Non-maintainer upload by the Debian LTS team. * d/patches/CVE-2024-28863.patch: Add patch to fix CVE-2024-28863. - Generating a large number of sub-folders can consume memory on the system and even crash the Node.js client within a few seconds using a path with too many sub-folders inside. * d/patches/CVE-2026-23745.patch: Add patch to fix CVE-2026-23745. - When preservePaths is false, the linkpath of Link (hardlink) and SymbolicLink entries fail to be sanitized, allowing malicious archives to bypass the extraction root restriction, leading to arbitrary file overwrites via hardlinks and symlink poisoning via absolute symlink targets. * d/patches/CVE-2026-23745-regression-fix.patch: Add patch to fix a regression introduced by the fix for CVE-2026-23745. - The fix for CVE-2026-23745 introduces a regression that prevents unpacking archives with valid linkpaths within the archive. * d/patches/CVE-2026-24842.patch: Add patch to fix CVE-2026-24842. - The security check for hardlink entries allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. * d/patches/CVE-2026-26960-1.patch, d/patches/CVE-2026-26960-2.patch: Add patch to fix CVE-2026-26960. - An attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. * d/patches/CVE-2026-29786.patch: Add patch to fix CVE-2026-29786. - An attacker-controlled archive can create a hardlink that points outside the extraction directory by using a drive-relative link target. * d/patches/CVE-2026-31802.patch: Add patch to fix CVE-2026-31802. - An attacker-controlled archive can create a hardlink that points outside the extraction directory by using a drive-relative link target. * d/patches/fix-tests.patch: Fix autopkgtest. Checksums-Sha1: 19f7bf9439b5ba52e0c965e77fc0e0362efb94bd 2954 node-tar_6.1.13+~cs7.0.5-1+deb12u1.dsc 5b1edc480bcd07723ea2646744119ae642690575 15081 node-tar_6.1.13+~cs7.0.5.orig-fs-minipass.tar.gz 5f953f183e36a15c6ce3f336568f6051b7b183f3 6515 node-tar_6.1.13+~cs7.0.5.orig-types-tar.tar.gz 66fb2ad2701e6cb6771d2d0e3886834e0385651d 136081 node-tar_6.1.13+~cs7.0.5.orig.tar.gz e7798949d00684c3595d4822aa3a33f338076b43 20072 node-tar_6.1.13+~cs7.0.5-1+deb12u1.debian.tar.xz b991572d9da0addb35a521124a47612d520a7637 23412 node-tar_6.1.13+~cs7.0.5-1+deb12u1_source.buildinfo Checksums-Sha256: ebed7d4f7514da9a91e49e0ce41355ac0549369ab48f2b69ee8182e9362d58d2 2954 node-tar_6.1.13+~cs7.0.5-1+deb12u1.dsc 6ccb0f341ce1d44f40df44eea3566577b7c3f79466fa0ade56a7ddc203c8980f 15081 node-tar_6.1.13+~cs7.0.5.orig-fs-minipass.tar.gz 3e97385fb828dfc00ff02f9b30a31a20c737404096cdb006cf7083157c7e1a5d 6515 node-tar_6.1.13+~cs7.0.5.orig-types-tar.tar.gz 3a109051a63b78a00830bf602036cc77b6870be68967a68e2ce1e0ad3eed8870 136081 node-tar_6.1.13+~cs7.0.5.orig.tar.gz c4171ff14a809b15fe6e9646715121cdc58368c78dc8c51e2f33106e0612d55d 20072 node-tar_6.1.13+~cs7.0.5-1+deb12u1.debian.tar.xz 332245a4ac4e4b3d266ee3934de577caff6c9887b7d7df3f2f32a5f1b08e3365 23412 node-tar_6.1.13+~cs7.0.5-1+deb12u1_source.buildinfo Files: 5c934165f2080f81573a37833184f0ec 2954 javascript optional node-tar_6.1.13+~cs7.0.5-1+deb12u1.dsc 9a75070e4b0f1c40732373897be2f125 15081 javascript optional node-tar_6.1.13+~cs7.0.5.orig-fs-minipass.tar.gz bbd2333b527227358e720aac52e97f93 6515 javascript optional node-tar_6.1.13+~cs7.0.5.orig-types-tar.tar.gz a4c0844eae14347dfda425d8f14ff608 136081 javascript optional node-tar_6.1.13+~cs7.0.5.orig.tar.gz ffb69ebb30acb13f6eab2be83d1247e3 20072 javascript optional node-tar_6.1.13+~cs7.0.5-1+deb12u1.debian.tar.xz a2d30634922f0d037c4ced2c7ab42f27 23412 javascript optional node-tar_6.1.13+~cs7.0.5-1+deb12u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvu1N7VVEpMA+KD3HS80FZ8KW0F0FAmptYlkACgkQS80FZ8KW 0F0ZKRAAn7J1+e/m8uokr4b8hT0qlCogU4QzQoMJHF7BbMk2pOkTLCCuuZBBOTwK prwOPQqfo072LPjLQc3og99gNzSeTEXEX0c7SGRbplRb8jvVqfX66tyLhGsH66ZM 6jQkYOgQfL5e7ndzKC9lB75BJ3Yhh/SD1/G2nyuOh6IYVt/0J0jSlY5PR8SF9v2q kQ13fdh2Z2uyRkICNvUXZ4HGMhI3sMbuv9BvLEAxrjycTBjpu9cQQwfAxbfMLQ4r Zsr+uTGPwjfjVzydvpsGt3ZRgxilDwH1EnLtn1U7qqwd3No/k9XKjRckj/HwPxRc MKiL723WEsW2ez4QVSqSDe338vDHyTTgtrNuSoK37gBNS3GdAjuy9WOMqFKVcTql RY0VHWvXzeqX0J8erwuLxSIyx8qQoc82PIcoVohcyx0zjv6B7S3uFSSl1QQY0hlD i31+ipG2r1hohrINiwajQTDciDm99kMsDN69ffYsyusjJmEv+h5MsZzhsuxI22r/ clsBSdH/o/yZLJ9uMrhRmjlTtpZU15hQ9wCu/CPtVW2/520Lk8BvtlkO/mTc8VvT +i0V8SFIptswU5rYjtMElq4U+fFtTQNP9UUPRODfSI0Q+Fk3v2zy9gik98kHxh4T wOEwPRnjYSHszwm3RQP06PwDJD9E6WA/R17tX6OsuGStnPGChYc= =kq/n -----END PGP SIGNATURE-----