
CVE-2026-5704: GNU tar: Listing/extraction desynchronization allows hidden file injection https://www.openwall.com/lists/oss-security/2026/04/11/10 -t and -x produce different results when processing archives containing non-data-bearing typeflags (symlink, chardev, blockdev, FIFO) with a non-zero size field
Post summary
The post discloses a GNU tar desynchronization flaw (CVE-2026-5704) that allows hidden file injection, providing technical details but no evidence of exploitation or mitigations.


