Use openat2 to jailify the extraction directory

This addresses CVE-2025-45582.
* gnulib.modules: Add openat2.
* src/misc.c (open_subdir): New static function.
(fdbase_opendir): Use it.
* src/tar.c (open_searchdir_how): New var, replacing and
augmenting open_searchdir_flags.  All uses changed.
* tests/extrac31.at: New file.
* tests/Makefile (TESTSUITE_AT), tests/testuite.at: Add it.
This commit is contained in:
Paul Eggert
2025-11-15 15:10:48 -08:00
parent aec5d77437
commit 75b03fdff4
10 changed files with 107 additions and 29 deletions
+4 -1
View File
@@ -1,4 +1,4 @@
GNU tar NEWS - User visible changes. 2025-11-09
GNU tar NEWS - User visible changes. 2025-11-13
Please send GNU tar bug reports to <bug-tar@gnu.org>
version 1.35.90 (git)
@@ -35,6 +35,9 @@ option.
* Bug fixes
** When extracting, tar no longer follows symbolic links to targets
outside the working directory.
** Fixed O(n^2) time complexity bug for large numbers of directories when
extracting with --delay-directory-restore or reading incremental archives.