tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a directory. Because fs::metadata() follows symbolic links, a crafted tarball containing a symlink entry followed by a directory entry with the same name causes the crate to treat the symlink target as a valid existing directory — and subsequently apply chmod to it. This allows an attacker to modify the permissions of arbitrary directories outside the extraction root. This issue has been fixed in version 0.4.45.
CVSS Details
- CVSS 4.0 Base Score: 5.1 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade rust | Mar 25, 2026 | Mar 20, 2026 |
| Amazon Linux Ami 2 | — | Upgrade rust-toolset-srpm-macrosUpgrade rust-srcUpgrade clippyUpgrade rust-docUpgrade rustUpgrade rustfmtUpgrade cargoUpgrade rust-std-staticUpgrade rust-toolsetUpgrade rust-debugger-commonUpgrade rust-analyzerUpgrade rust-gdb | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade rust-std-staticUpgrade clamav1.5-debugsourceUpgrade clippy-debuginfoUpgrade clamav1.5-milter-debuginfoUpgrade clamav1.5-develUpgrade clamd1.5Upgrade rust-toolset-srpm-macrosUpgrade rust-debuginfoUpgrade cargo-cUpgrade belowUpgrade clippyUpgrade cargo-debuginfoUpgrade below-debuginfoUpgrade clamav1.5-milterUpgrade rust-debugger-commonUpgrade clamav1.5-freshclam-debuginfoUpgrade rustUpgrade clamav1.5-lib-debuginfoUpgrade cargo-c-debuginfoUpgrade rust-analyzerUpgrade rust-below-debugsourceUpgrade rust-std-static-wasm32-unknown-unknownUpgrade rustfmtUpgrade rust-docUpgrade rust-lldbUpgrade rust-gdbUpgrade rust-cargo-c-debugsourceUpgrade clamav1.5-dataUpgrade rust-debugsourceUpgrade clamd1.5-debuginfoUpgrade clamav1.5-filesystemUpgrade rust-std-static-wasm32-wasip1Upgrade rust-analyzer-debuginfoUpgrade clamav1.5-libUpgrade rustfmt-debuginfoUpgrade rust-srcUpgrade rust-toolsetUpgrade clamav1.5Upgrade clamav1.5-freshclamUpgrade clamav1.5-docUpgrade cargoUpgrade clamav1.5-debuginfo | Apr 14, 2026 | Mar 20, 2026 |
| Debian | — | Upgrade rustc | Sep 21, 2026 | Mar 20, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Mar 20, 2026 |
| Ubuntu | — | Upgrade rustc-1.81Upgrade rustc-1.62Upgrade rustc-1.79Upgrade rustc-1.88Upgrade librust-cargo-c-devUpgrade rustc-1.76Upgrade rustc-1.91Upgrade rustc-1.83Upgrade rustc-1.84Upgrade rustc-1.78Upgrade librust-tar+default-devUpgrade rustc-1.85Upgrade librust-tar-devUpgrade rustcUpgrade rustc-1.89Upgrade rustc-1.82Upgrade rustc-1.74Upgrade rustc-1.80Upgrade rustc-1.77Upgrade cargo-c | Apr 2, 2026 | Mar 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub