Debian alert DLA-4712-1 (node-tar)
| From: | Daniel Leidert <dleidert@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4712-1] node-tar security update | |
| Date: | Sat, 01 Aug 2026 17:34:05 +0200 | |
| Message-ID: | <3aa85c3640b8619daea33526b2135c799c492081.camel@debian.org> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4712-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Daniel Leidert August 01, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : node-tar Version : 6.1.13+~cs7.0.5-1+deb12u1 CVE ID : CVE-2024-28863 CVE-2026-23745 CVE-2026-26960 CVE-2026-29786 Multiple vulnerabilities have been discovered in node-tar, a Node.js module to read and write portable tar archives. CVE-2024-28863 Generating a large number of sub-folders can consume memory on the system and even crash the Node.js client within a few seconds using a path with too many sub-folders inside. CVE-2026-23745 When preservePaths is false, the linkpath of Link (hardlink) and SymbolicLink entries fail to be sanitized, allowing malicious archives to bypass the extraction root restriction, leading to arbitrary file overwrites via hardlinks and symlink poisoning via absolute symlink targets. The fix for this issue introduces CVE-2026-24842 and CVE-2026-31802. Both have been fixed subsequently. CVE-2026-26960 An attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. CVE-2026-29786 An attacker-controlled archive can create a hardlink that points outside the extraction directory by using a drive-relative link target. For Debian 12 bookworm, these problems have been fixed in version 6.1.13+~cs7.0.5-1+deb12u1. We recommend that you upgrade your node-tar packages. For the detailed security status of node-tar please refer to its security tracker page at: https://security-tracker.debian.org/tracker/node-tar Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQJIBAABCgAyFiEEvu1N7VVEpMA+KD3HS80FZ8KW0F0FAmpuEe0UHGRsZWlkZXJ0 QGRlYmlhbi5vcmcACgkQS80FZ8KW0F0B1hAAptduDX2Tfn/y1dhO9mlKe3Plbxzs JxPV7+dpFSSjSWaz6py6pPH/LgUyGShJlWdE/HzEIPOLTxTux7B6JdMePNyrxb1E DGzhqBBHoXLPCmMps2ZRKSakauXJ4EFx3MtJmkedFab4Edzz9nwONolviyVNMT5k 84UH+Lg+bXwstuKYth6Zdg7lo2eSHWpSes+lZtj4Joq4Zy8xSNfe4zNAU9LZaQ0R CzsZeH5sJhnFldu+mcxjmG7+TNNNPpRuh3MV0B8iw1BxZzHUmz8CbSYvbD43MnLi gqSgef2i36DTpVCODrzzD+KSxaiaU2H7CkTdZNg8yMhs9zf83d923I1PK8Ivh2Me ihrPDDJGWOJOkDhCPXhl7IVfAOKv1/nPgSPFVmifyjGdmpY2jYLmOckV9EnAQ/uj ybwb3r4lkTRVWL73mzxDLJfdLlR5wMYIhrF/AGXDDMZV3G9c5tOQSzJ8+mV0G2sn dxssa5iSdCFapkZAOJq/jy+YAHQUwEokvSYbK9seKEqtYYc9HZpgJJgtNqgklGR/ oUKbpgBNDlDiinbWWYY2p557OOenD6NfEJ4C7qJA/cwfqZJ2FT4UvjvHNPPgmgpB BtUjWN3CpEs4KcPk0AepzAkI3K+6tZL2w01S6iQO6bnTxPH4StZo5iX3HIntxfqq 1XP3tPdjrWmS+pU= =iycG -----END PGP SIGNATURE-----
