CVE-2026-33056Patch(tar_project / tar)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tar_project tar systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a directory. Because fs::metadata() follows symbolic links, a crafted tarball containing a symlink entry followed by a directory entry with the same name causes the crate to treat the symlink target as a valid existing directory — and subsequently apply chmod to it. This allows an attacker to modify the permissions of arbitrary directories outside the extraction root. This issue has been fixed in version 0.4.45.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-61

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tar

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 7d ago at 3 mentions (2026-03-23); latest day: 1
  • 11 total mentions across 8 days

Affected systems

Products
tar

Deep dive

Activity timeline11 mentions / 8d
01223Mentions · 2026-03-23: 3Mentions · 2026-03-26: 1Mentions · 2026-03-29: 1Mentions · 2026-03-31: 2Mentions · 2026-04-01: 1Mentions · 2026-04-03: 1Mentions · 2026-04-20: 1Mentions · 2026-05-06: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-29: 1Patch / Workaround · 2026-03-31: 2Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-03: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-29: 1Technical Details · 2026-03-31: 2Technical Details · 2026-04-01: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-20: 1Technical Details · 2026-05-06: 103-2303-2603-2903-3104-0104-0304-2005-06
Signal classification3 categories
Patch
545.5%
Disclosure
436.4%
General
218.2%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-233
Disclosure1General1Patch1
2026-03-261
General1
2026-03-291
Patch1
2026-03-312
Patch2
2026-04-011
Patch1
2026-04-031
Disclosure1
2026-04-201
Disclosure1
2026-05-061
Disclosure1
Full discourse11 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    ⚠️ Rust Security Alert: CVE-2026-33056 in `tar` crate (used by Cargo) lets malicious crates alter arbitrary dir perms during builds! Update Cargo, audit deps. Supply chain strikes again. https://blog.rust-lang.org/2026/03/21/cve-2026-33056/ #Rust #Cargo

    Post summary

    The post announces CVE-2026-33056, detailing how malicious crates can change directory permissions during Cargo builds and urges updating Cargo and auditing dependencies. No PoC, exploit, or active exploitation is reported.

    030120112
    1.4K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    CVE-2026-33056 — Rust tar crate issue affecting build-time directory permissions. ⚠️ CVE-2026-33056 (Rust tar crate): malicious crates can alter dir perms during builds. Supply-chain risk, not just a bug. https://github.com/rust-lang/crates.io

    Post summary

    The post discloses CVE‑2026‑33056, a Rust tar crate vulnerability that lets malicious crates modify build‑time directory permissions, but it offers no PoC, exploit, or mitigation details.

    1001050
    1.0K followersView on X
  • Rust Bytes 🦀@rustaceans_rs
    General

    link: https://blog.rust-lang.org/2026/03/21/cve-2026-33056/

    Post summary

    The text only cites a link to a Rust blog post about CVE‑2026‑33056, offering no further information or context.

    00011238
    4.9K followersView on X
  • Jeremy Morgan@JeremyCMorgan
    Patch

    Rust disclosed a CVE in the tar crate used by Cargo: a malicious crate can change permissions on arbitrary directories during package extraction. The vulnerable step is build-time extraction, so the exposure lands on CI runners and developer machines. Rust 1.94.1 is planned for March 26 with a fix. https://blog.rust-lang.org/2026/03/21/cve-2026-33056/

    Post summary

    Rust has disclosed CVE-2026-33056, a vulnerability in the tar crate allowing permission changes during build-time extraction, and plans a fix in Rust 1.94.1 released on March 26.

    0100075
    34.5K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Fedora fixes critical StGit flaw CVE-2026-33056 in Fedora 42 and 43 that lets crafted tar archives arbitrarily modify directory permissions, patch now via dnf. https://threatcluster.io/cluster/critical-permission-modification-vulnerability-in-fedora-stg-f1515d50

    Post summary

    Fedora 42 and 43 have released a patch via dnf for CVE-2026-33056, a critical StGit flaw that allows crafted tar archives to arbitrarily change directory permissions.

    01000104
    128 followersView on X
  • Michael Martino@battista212
    Patch

    CVE-2026-33056 in Rust tar crate allows malicious packages to modify filesystem permissions during Cargo extraction. http://crates.io blocked exploitation March 13, no published crates exploited. Alternative registries still exposed until Rust 1.94.1 ships March 26. Upgrade immediately.

    Post summary

    CVE-2026-33056 lets malicious Rust packages alter file permissions during extraction, but has not been actively exploited yet. A patch is included in Rust 1.94.1 (due March 26); users should upgrade immediately.

    100009
    160 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 astral-tokio-tar, Symlink directory permission modification, #CVE-2026-33056 (Moderate) https://dailycve.com/astral-tokio-tar-symlink-directory-permission-modification-cve-2026-33056-moderate/

    Post summary

    CVE-2026-33056 is disclosed as a moderate‑severity symlink directory permission modification vulnerability, with no evidence of a PoC, exploit, or patch mentioned.

    0000022
    196 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Fedora 44 fixes critical CVE-2026-33056 in sched_ext BPF schedulers rust-scx_rusty, rust-scx_layered, rust-scx_rustland, users urged to dnf update to rust-tar 0.4.45 builds. https://threatcluster.io/cluster/critical-cve-2026-33056-affects-fedora-44-scheduler-componen-a27e0769

    Post summary

    This announcement highlights that Fedora 44 has addressed the critical CVE-2026-33056 affecting its sched_ext BPF schedulers, urging users to update to rust-tar 0.4.45 to mitigate the vulnerability.

    0000061
    128 followersView on X
  • ThreatCluster@threatcluster
    Patch

    JUST IN: Fedora 42 patches CVE-2026-33056 by rebuilding Rust components with rust-tar 0.4.45, shipping rust-cargo-c 0.10.19-2 and rust-ingredients 0.2.2-3 updates. https://threatcluster.io/cluster/fedora-42-rust-components-vulnerability-cve-2026-33056-addre-3639855d

    Post summary

    Fedora 42 has released updates to mitigate CVE‑2026‑33056 by rebuilding Rust components, and while details of the vulnerability type are implied, no PoC or active exploitation is reported.

    0000024
    128 followersView on X
  • Michael@woollardm8
    Disclosure

    https://blog.rust-lang.org/2026/03/21/cve-2026-33056/?utm_source=tldrinfosec

    Post summary

    The input references a Rust blog post about CVE-2026-33056, but no substantive details are provided in the text to confirm any specific indicators.

    0000032
    3.3K followersView on X
  • TRONCAL Yannick@ytroncal
    General

    RUST : Security advisory for Cargo https://blog.rust-lang.org/2026/03/21/cve-2026-33056/

    Post summary

    The post notes a Rust security advisory for Cargo (CVE-2026-33056) but offers no substantive detail about the vulnerability, exploitation, or mitigation.

    0000017
    139 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptar_projecttar-rust-

Explore more