CVE-2026-5704Disclosure(gnu / enterprise_linux)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gnu enterprise_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • hardened_images
  • tar

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-11); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
enterprise_linuxhardened_imagestar

6 versions affected across 3 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-11: 2Mentions · 2026-06-02: 1Patch / Workaround · 2026-06-02: 1Technical Details · 2026-04-11: 2Technical Details · 2026-06-02: 104-1106-02
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-112
Disclosure2
2026-06-021
Patch1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-5704: GNU tar: Listing/extraction desynchronization allows hidden file injection https://www.openwall.com/lists/oss-security/2026/04/11/10 -t and -x produce different results when processing archives containing non-data-bearing typeflags (symlink, chardev, blockdev, FIFO) with a non-zero size field

    Post summary

    The post discloses a GNU tar desynchronization flaw (CVE-2026-5704) that allows hidden file injection, providing technical details but no evidence of exploitation or mitigations.

    1501451.6K
    4.6K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Ubuntu and Mageia patch tar flaws CVE-2024-12905, CVE-2025-48387, CVE-2025-59343, CVE-2026-5704 letting remote attackers overwrite files and inject hidden content via malicious archives. https://threatcluster.io/cluster/multiple-cves-discovered-in-tar-affecting-ubuntu-and-mageia--167df302

    Post summary

    The tweet announces that Ubuntu and Mageia have released patches to address several CVE‑identified tar flaws that allow remote file overwrite and hidden content injection. No PoC, exploit tool, or active exploitation is reported.

    0000059
    294 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5704 Remote File Injection Vulnerability in Tar via Malicious Archive Crafting https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5704

    Post summary

    The post announces CVE-2026-5704, stating it is a Remote File Injection vulnerability in Tar triggered by malicious archive crafting; no exploit code, patch, or active use is mentioned.

    0000040
    4.0K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appgnutar---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
Appredhathardened_images---

Explore more