- What: A vulnerability in the tar utility allows file overwriting.
- Impact: Users of Ubuntu systems may be affected if they extract malicious archives.
Ubuntu Security Notices USN-8477-1 USN-8477-1: tar vulnerability Publication date 25 June 2026 Overview tar could be made to overwrite files if it opened a specially crafted archive. Releases 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS 14.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages tar - GNU tar archive utility Details It was discovered that tar incorrectly handled certain crafted archive files. An attacker could possibly use this to inject hidden files with attacker-controlled content, bypassing pre-extraction inspection mechanisms. It was discovered that tar incorrectly handled certain crafted archive files. An attacker could possibly use this to inject hidden files with attacker-controlled content, bypassing pre-extraction inspection mechanisms. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 26.04 LTS resolute tar – 1.35+dfsg-4ubuntu0.1 24.04 LTS noble tar – 1.35+dfsg-3ubuntu0.1 22.04 LTS jammy tar – 1.34+dfsg-1ubuntu0.1.22.04.3 20.04 LTS focal tar – 1.30+dfsg-7ubuntu0.20.04.4+esm1 Ubuntu Pro Fix available with Ubuntu Pro . 18.04 LTS bionic tar – 1.29b-2ubuntu0.4+esm2 Ubuntu Pro Fix available with Ubuntu Pro . 16.04 LTS xenial tar – 1.28-2.1ubuntu0.2+esm4 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. 14.04 LTS trusty tar – 1.27.1-1ubuntu0.1+esm5 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-5704 CVE-2026-5704