{"id":"USN-8367-1","summary":"node-tar-fs vulnerabilities","details":"It was discovered that tar-fs did not properly limit paths when\nextracting crafted tar files. An attacker could possibly use this\nissue to write or overwrite files outside the intended extraction\ndirectory. This issue only affected Ubuntu 22.04 LTS and Ubuntu\n24.04 LTS. (CVE-2024-12905)\n\nIt was discovered that tar-fs did not properly validate extraction\npaths for certain crafted tar archives. An attacker could possibly\nuse this issue to write files outside the intended extraction\ndirectory. This issue only affected Ubuntu 22.04 LTS and Ubuntu\n24.04 LTS. (CVE-2025-48387)\n\nIt was discovered that tar-fs had a symlink validation bypass when\nextracting crafted tar files. An attacker could possibly use this\nissue to write files outside the intended extraction directory.\n(CVE-2025-59343)","modified":"2026-06-02T18:29:28.949589207Z","published":"2026-06-02T13:00:16Z","related":["UBUNTU-CVE-2024-12905","UBUNTU-CVE-2025-48387","UBUNTU-CVE-2025-59343"],"upstream":["CVE-2024-12905","CVE-2025-48387","CVE-2025-59343","UBUNTU-CVE-2024-12905","UBUNTU-CVE-2025-48387","UBUNTU-CVE-2025-59343"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8367-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-12905"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-48387"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-59343"}],"affected":[{"package":{"name":"node-tar-fs","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/node-tar-fs?arch=source&distro=esm-apps%2Fjammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.1-6ubuntu0.22.04.1~esm1"}]}],"versions":["2.1.1-2","2.1.1-4","2.1.1-6"],"ecosystem_specific":{"binaries":[{"binary_version":"2.1.1-6ubuntu0.22.04.1~esm1","binary_name":"node-tar-fs"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8367-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:22.04:LTS","cves":[{"id":"CVE-2024-12905","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2025-48387","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-59343"}]}}},{"package":{"name":"node-tar-fs","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/node-tar-fs?arch=source&distro=esm-apps%2Fnoble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.1-6ubuntu0.24.04.1~esm1"}]}],"versions":["2.1.1-6"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_version":"2.1.1-6ubuntu0.24.04.1~esm1","binary_name":"node-tar-fs"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:24.04:LTS","cves":[{"id":"CVE-2024-12905","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-48387"},{"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2025-59343"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8367-1.json"}},{"package":{"name":"node-tar-fs","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/node-tar-fs?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.9+~cs2.0.4-1+deb13u1build0.25.10.1"}]}],"versions":["2.1.1-6","3.0.8+~cs2.0.4-1","3.0.9+~cs2.0.4-1"],"ecosystem_specific":{"binaries":[{"binary_version":"3.0.9+~cs2.0.4-1+deb13u1build0.25.10.1","binary_name":"node-tar-fs"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:25.10","cves":[{"id":"CVE-2025-59343","severity":[{"score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"score":"medium","type":"Ubuntu"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8367-1.json"}}],"schema_version":"1.7.5"}