Echo: tar: security update to 1.35+dfsg-3.1+e5

medium Tenable Self-Hosted Container Security Plugin ID 461012

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling
allows a local attacker with write access to a directory being backed up to influence the restore process
if the attacker has access to the system where the restore is being performed. During restoration, files
or directories may be created, renamed or overwritten outside the intended extraction directory. This
could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does
not require the attacker to modify or craft the archive, and standard backup and restore
workflows—including extracting into a newly created directory without using the -P option do not mitigate
the issue. (CVE-2026-18477)

Solution

Update the tar library and its related packages to version 1.35+dfsg-3.1+e5 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-18477

Plugin Details

Severity: Medium

ID: 461012

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.62

CVSS v2

Risk Factor: Low

Base Score: 3.8

Temporal Score: 2.8

Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:C/A:N

CVSS Score Source: CVE-2026-18477

CVSS v3

Risk Factor: Medium

Base Score: 4.4

Temporal Score: 3.9

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/4/2026

Vulnerability Publication Date: 8/3/2026

Reference Information

CVE: CVE-2026-18477