{"id":"SUSE-SU-2026:2615-1","summary":"Security update for tar","details":"This update for tar fixes the following issues:\n\nUpgrade tar to version 1.34 (jsc#PED-16073).\n\nSecurity issues fixed:\n\n- CVE-2025-45582: file overwrite via directory traversal in crafted TAR archives (bsc#1246399).\n\nOther updates and bugfixes:\n\n* Changes from 1.28:\n  - New --one-top-level option: extract all files into a subdirectory named after the archive base name\n  - New --sort option: sort directory entries by name or inode when creating archives\n  - New exclusion options: --exclude-ignore, --exclude-ignore-recursive, and --exclude-vcs-ignores\n  - New checkpoint action: totals; extended checkpoint format specifiers\n  - Official tar(1) and rmt(8) manpages now provided upstream\n  - Refuse to read from or write archives to a tty device\n* Changes from 1.29:\n  - New --verbatim-files-from option: treat each line in a file list as a literal file name regardless of leading\n    dashes\n* Changes from 1.30:\n  - Member names containing '..' components are now skipped on extraction (security hardening)\n  - Erroneous use of position-sensitive options is now reported\n  - --numeric-owner now applies to private (pax) headers too\n  - Fixed --delay-directory-restore in several edge cases\n  - New --warnings=failed-read option to suppress unreadable-file warnings when combined with --ignore-failed-read\n* Changes from 1.32:\n  - POSIX extended format headers no longer include PID by default\n  - Wildcards in --exclude-vcs-ignore mode no longer match slashes\n  - Fixed --no-overwrite-dir option\n  - Fixed handling of chained renames in incremental backups\n  - Link counting works for file names supplied via -T\n* Changes from 1.33:\n  - Fix extraction over pipe\n  - Fix memory leak in read_header\n  - Fix extraction when . and .. are unreadable\n  - Gracefully handle duplicate symlinks when extracting\n  - Re-initialise supplementary groups when switching to user privileges\n","modified":"2026-06-25T06:15:06.871826685Z","published":"2026-06-24T09:02:36Z","related":["CVE-2025-45582"],"upstream":["CVE-2025-45582"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262615-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246399"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-45582"}],"affected":[{"package":{"name":"tar","ecosystem":"SUSE:Linux Enterprise Server 12 SP5-LTSS","purl":"pkg:rpm/suse/tar&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.34-15.27.1"}]}],"ecosystem_specific":{"binaries":[{"tar-lang":"1.34-15.27.1","tar":"1.34-15.27.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2615-1.json"}},{"package":{"name":"tar","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/tar&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.34-15.27.1"}]}],"ecosystem_specific":{"binaries":[{"tar":"1.34-15.27.1","tar-lang":"1.34-15.27.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2615-1.json"}}],"schema_version":"1.7.5"}