Debian Package Tracker
Register | Log in
Subscribe

tar

Choose email to subscribe with

general
  • source: tar (main)
  • version: 1.35+dfsg-5
  • maintainer: Janos Lenart (DMD)
  • uploaders: Carl Worth [DMD]
  • arch: all any
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.34+dfsg-1+deb11u1
  • oldstable: 1.34+dfsg-1.2+deb12u1
  • stable: 1.35+dfsg-3.1
  • testing: 1.35+dfsg-4
  • unstable: 1.35+dfsg-5
versioned links
  • 1.34+dfsg-1+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.34+dfsg-1.2+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.35+dfsg-3.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.35+dfsg-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.35+dfsg-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • tar (91 bugs: 0, 49, 42, 0)
  • tar-scripts
action needed
3 security issues in trixie high

There are 3 open security issues in trixie.

2 important issues:
  • CVE-2026-18477: A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
  • CVE-2026-18508: A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
1 issue left for the package maintainer to handle:
  • CVE-2026-5704: (needs triaging) A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-04-06 Last update: 2026-08-08 18:30
3 security issues in sid high

There are 3 open security issues in sid.

3 important issues:
  • CVE-2026-5704: A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.
  • CVE-2026-18477: A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
  • CVE-2026-18508: A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
Created: 2026-04-06 Last update: 2026-08-08 18:30
3 security issues in forky high

There are 3 open security issues in forky.

3 important issues:
  • CVE-2026-5704: A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.
  • CVE-2026-18477: A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
  • CVE-2026-18508: A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
Created: 2026-04-06 Last update: 2026-08-08 18:30
3 security issues in bullseye high

There are 3 open security issues in bullseye.

2 important issues:
  • CVE-2026-18477: A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
  • CVE-2026-18508: A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
1 issue postponed or untriaged:
  • CVE-2026-5704: (postponed; to be fixed through a stable update) A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.
Created: 2026-08-03 Last update: 2026-08-08 18:30
3 security issues in bookworm high

There are 3 open security issues in bookworm.

2 important issues:
  • CVE-2026-18477: A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
  • CVE-2026-18508: A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
1 issue postponed or untriaged:
  • CVE-2026-5704: (needs triaging) A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.
Created: 2026-08-03 Last update: 2026-08-08 18:30
3 bugs tagged patch in the BTS normal
The BTS contains patches fixing 3 bugs, consider including or untagging them.
Created: 2026-06-02 Last update: 2026-08-09 04:30
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2026-07-04 Last update: 2026-08-09 02:36
lintian reports 5 warnings normal
Lintian reports 5 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-08-08 Last update: 2026-08-08 22:01
debian/patches: 7 patches to forward upstream low

Among the 8 debian patches available in version 1.35+dfsg-5 of the package, we noticed the following issues:

  • 7 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-08-08 19:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.6.2).
Created: 2024-04-07 Last update: 2026-08-08 18:02
testing migrations
  • excuses:
    • Migration status for tar (1.35+dfsg-4 to 1.35+dfsg-5): BLOCKED: Maybe temporary, maybe blocked but Britney is missing information (check below)
    • Issues preventing migration:
    • ∙ ∙ Missing build on riscv64
    • ∙ ∙ Piuparts check waiting for test results - https://piuparts.debian.org/sid/source/t/tar.html
    • ∙ ∙ Autopkgtest deferred on riscv64: missing arch:riscv64 build
    • ∙ ∙ Autopkgtest for cedar-backup3: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, loong64: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for createrepo-c: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, loong64: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for cross-toolchain-base: amd64: Test triggered (will not be considered a regression) ♻ (reference ♻), arm64: Test triggered (will not be considered a regression) ♻ (reference ♻), armhf: Test triggered (will not be considered a regression) ♻ (reference ♻), i386: Test triggered (will not be considered a regression) ♻ (reference ♻), loong64: Test triggered, ppc64el: Test triggered (will not be considered a regression) ♻ (reference ♻), s390x: Test triggered (will not be considered a regression) ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for dpkg: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, loong64: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for lava: amd64: Test triggered, arm64: Test triggered (will not be considered a regression) ♻ (reference ♻), armhf: Test triggered, i386: Test triggered, loong64: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for pristine-tar: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, loong64: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for python-bcbio-gff: amd64: Test triggered, arm64: Test triggered, armhf: Test triggered, i386: Test triggered, loong64: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Lintian check waiting for test results on arm64, amd64, riscv64, ppc64el, i386, armhf - info
    • ∙ ∙ Reproducibility check waiting for results on amd64 - info
    • ∙ ∙ Reproducibility check waiting for results on arm64 - info
    • ∙ ∙ Reproducibility check waiting for results on armhf - info
    • ∙ ∙ Reproducibility check waiting for results on i386 - info
    • ∙ ∙ Too young, only 1 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Updating tar will fix bugs in testing: #1141146
    • Not considered
news
[rss feed]
  • [2026-08-08] Accepted tar 1.35+dfsg-5 (source) into unstable (Simon Josefsson)
  • [2026-02-26] tar 1.35+dfsg-4 MIGRATED to testing (Debian testing watch)
  • [2026-02-19] Accepted tar 1.35+dfsg-4 (source) into unstable (Luca Boccassi)
  • [2024-12-24] tar 1.35+dfsg-3.1 MIGRATED to testing (Debian testing watch)
  • [2024-12-19] Accepted tar 1.35+dfsg-3.1 (source) into unstable (Reinhard Tartler) (signed by: Gianfranco Costamagna)
  • [2024-03-09] Accepted tar 1.30+dfsg-6+deb10u1 (source) into oldoldstable (Adrian Bunk)
  • [2024-01-20] Accepted tar 1.34+dfsg-1+deb11u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2024-01-20] Accepted tar 1.34+dfsg-1.2+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2024-01-17] tar 1.35+dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2024-01-12] Accepted tar 1.35+dfsg-3 (source) into unstable (Helmut Grohne) (signed by: Gianfranco Costamagna)
  • [2024-01-03] tar 1.35+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2023-12-29] Accepted tar 1.35+dfsg-2 (source) into unstable (Gianfranco Costamagna)
  • [2023-12-28] Accepted tar 1.35+dfsg-1 (source) into unstable (Gianfranco Costamagna)
  • [2023-12-25] tar 1.34+dfsg-1.4 MIGRATED to testing (Debian testing watch)
  • [2023-12-20] Accepted tar 1.34+dfsg-1.4 (source) into unstable (Gianfranco Costamagna)
  • [2023-12-19] tar 1.34+dfsg-1.3 MIGRATED to testing (Debian testing watch)
  • [2023-12-13] Accepted tar 1.34+dfsg-1.3 (source) into unstable (Salvatore Bonaccorso)
  • [2023-04-14] tar 1.34+dfsg-1.2 MIGRATED to testing (Debian testing watch)
  • [2023-04-08] Accepted tar 1.34+dfsg-1.2 (source) into unstable (Paul Gevers)
  • [2022-11-20] Accepted tar 1.34+dfsg-1.1 (source) into unstable (Mechtilde Stehmann)
  • [2021-11-28] Accepted tar 1.29b-1.1+deb9u1 (source) into oldoldstable (Adrian Bunk)
  • [2021-02-27] tar 1.34+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2021-02-17] Accepted tar 1.34+dfsg-1 (source) into unstable (Janos Lenart)
  • [2021-02-12] Accepted tar 1.33+dfsg-1 (source) into unstable (Janos Lenart)
  • [2020-12-01] tar 1.32+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-11-26] Accepted tar 1.32+dfsg-1 (source) into unstable (Janos Lenart)
  • [2020-03-20] tar 1.30+dfsg-7 MIGRATED to testing (Debian testing watch)
  • [2020-03-14] Accepted tar 1.30+dfsg-7 (source) into unstable (Bdale Garbee)
  • [2019-04-29] tar 1.30+dfsg-6 MIGRATED to testing (Debian testing watch)
  • [2019-04-23] Accepted tar 1.30+dfsg-6 (source amd64) into unstable (Bdale Garbee)
  • 1
  • 2
bugs [bug history graph]
  • all: 92 96
  • RC: 0
  • I&N: 49 52
  • M&W: 43 44
  • F&P: 0
  • patch: 3
links
  • homepage
  • lintian (0, 5)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • l10n (-, 85)
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.35+dfsg-4

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing