ELA-1838-1 node-tar security update

multiple vulnerabilities

2026-10-01
Packagenode-tar
Version4.4.6+ds1-3+deb10u3 (buster)
Related CVEs CVE-2024-28863 CVE-2026-23745 CVE-2026-26960 CVE-2026-29786


Multiple vulnerabilities have been discovered in node-tar, a Node.js module to read and write portable tar archives.

CVE-2024-28863

Generating a large number of sub-folders can consume memory on the system and even crash the Node.js client within a few seconds using a path with too many sub-folders inside.

CVE-2026-23745

When preservePaths is false, the linkpath of Link (hardlink) and SymbolicLink entries fail to be sanitized, allowing malicious archives to bypass the extraction root restriction, leading to arbitrary file overwrites via hardlinks and symlink poisoning via absolute symlink targets.

The fix for this issue introduces CVE-2026-24842 and CVE-2026-31802. Both have been fixed subsequently.

CVE-2026-26960

An attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user.

CVE-2026-29786

An attacker-controlled archive can create a hardlink that points outside the extraction directory by using a drive-relative link target.



For Debian 10 buster, these problems have been fixed in version 4.4.6+ds1-3+deb10u3.

We recommend that you upgrade your node-tar packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.