Bug 2379592 (CVE-2025-45582)
| Summary: | CVE-2025-45582 tar: Tar path traversal | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | achen, gmalinko, janstey, pdelbell, praiskup, rhel-process-autobot, rstepani, source2806, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in GNU Tar. An attacker could exploit this vulnerability by providing two specially crafted TAR archives, if those archives were extracted in the same directory. The first archive contains a symbolic link that points to a critical directory. The second archive, when extracted, uses this symbolic link to overwrite sensitive files on the system, bypassing existing directory traversal protections. This could lead to unauthorized file modification or, in some cases, privilege escalation.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2380006, 2380007 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2025-07-11 17:01:11 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:0002 https://access.redhat.com/errata/RHSA-2026:0002 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:0067 https://access.redhat.com/errata/RHSA-2026:0067 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:0135 https://access.redhat.com/errata/RHSA-2026:0135 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:0434 https://access.redhat.com/errata/RHSA-2026:0434 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:0435 https://access.redhat.com/errata/RHSA-2026:0435 When this patch will be available for RHEL 8? Will there be a fix for CVE-2025-45582 on CentOS Stream 9? |