tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a directory. Because fs::metadata() follows symbolic links, a crafted tarball containing a symlink entry followed by a directory entry with the same name causes the crate to treat the symlink target as a valid existing directory — and subsequently apply chmod to it. This allows an attacker to modify the permissions of arbitrary directories outside the extraction root. This issue has been fixed in version 0.4.45.
CVSS Details
- CVSS 4.0 Base Score: 5.1 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade rust | Mar 25, 2026 | Mar 20, 2026 |
| Amazon Linux Ami 2 | — | Upgrade rust-analyzerUpgrade rust-std-staticUpgrade rust-gdbUpgrade rust-debugger-commonUpgrade rust-toolsetUpgrade cargoUpgrade rustUpgrade rust-docUpgrade rustfmtUpgrade clippyUpgrade rust-srcUpgrade rust-toolset-srpm-macros | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade rustUpgrade rust-debugger-commonUpgrade clamav1.5-milter-debuginfoUpgrade clamav1.5-milterUpgrade rust-debuginfoUpgrade cargo-c-debuginfoUpgrade cargo-cUpgrade clamd1.5Upgrade clippy-debuginfoUpgrade belowUpgrade rust-std-staticUpgrade cargo-debuginfoUpgrade clamav1.5-lib-debuginfoUpgrade clippyUpgrade below-debuginfoUpgrade clamav1.5-debugsourceUpgrade rust-toolset-srpm-macrosUpgrade clamav1.5-develUpgrade clamav1.5-freshclam-debuginfoUpgrade rust-analyzer-debuginfoUpgrade clamav1.5-libUpgrade clamav1.5Upgrade rust-debugsourceUpgrade clamd1.5-debuginfoUpgrade rustfmtUpgrade rust-docUpgrade clamav1.5-filesystemUpgrade rust-std-static-wasm32-wasip1Upgrade rust-lldbUpgrade rust-gdbUpgrade rust-analyzerUpgrade clamav1.5-debuginfoUpgrade cargoUpgrade rustfmt-debuginfoUpgrade rust-toolsetUpgrade rust-below-debugsourceUpgrade rust-srcUpgrade clamav1.5-docUpgrade rust-cargo-c-debugsourceUpgrade clamav1.5-freshclamUpgrade clamav1.5-dataUpgrade rust-std-static-wasm32-unknown-unknown | Apr 14, 2026 | Mar 20, 2026 |
| Debian | — | Upgrade rustc | Sep 21, 2026 | Mar 20, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Mar 20, 2026 |
| Ubuntu | — | Upgrade cargo-cUpgrade rustc-1.89Upgrade rustc-1.82Upgrade rustc-1.77Upgrade rustc-1.74Upgrade rustc-1.80Upgrade rustcUpgrade librust-cargo-c-devUpgrade rustc-1.91Upgrade librust-tar-devUpgrade rustc-1.81Upgrade rustc-1.62Upgrade rustc-1.85Upgrade librust-tar+default-devUpgrade rustc-1.78Upgrade rustc-1.76Upgrade rustc-1.84Upgrade rustc-1.83Upgrade rustc-1.79Upgrade rustc-1.88 | Apr 2, 2026 | Mar 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub