- Package:
- src:golang-github-moby-go-archive
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-08-28 19:21:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for golang-github-moby-go-archive. CVE-2026-17106[0]: | The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, | Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine | filesystem operations to the destination directory. The extractor | decides where each archive entry lands using lexical string checks | and then performs the filesystem operation on a path that is | resolved by the OS, so links introduced by the archive can be | followed out of the destination directory. An attacker who controls | the contents of an archive can create or overwrite files at | arbitrary paths writable by the extracting process. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-17106 https://www.cve.org/CVERecord?id=CVE-2026-17106 [1] https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
golang-github-moby-go-archive, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1145200@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Mathias Gibbens <gibmat@debian.org> (supplier of updated golang-github-moby-go-archive package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 28 Aug 2026 14:07:41 +0000
Source: golang-github-moby-go-archive
Architecture: source
Version: 0.3.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org>
Changed-By: Mathias Gibbens <gibmat@debian.org>
Closes: 1145200
Changes:
golang-github-moby-go-archive (0.3.3-1) unstable; urgency=medium
.
* New upstream release
- Includes fix for CVE-2026-17106 (Closes: #1145200)
* Update Standards-Version to 4.7.4 in d/control (no changes needed)
Checksums-Sha1:
3394e8a58c945117d537d3b1b5b1b684d850bf6b 2491 golang-github-moby-go-archive_0.3.3-1.dsc
ae1118902b3edb3fd92c0c8d2f43f91070cb588d 98546 golang-github-moby-go-archive_0.3.3.orig.tar.gz
a7d24c41eeb583b07b2e4874b2eca20a4d5a0889 3140 golang-github-moby-go-archive_0.3.3-1.debian.tar.xz
c53a952c871bac489060cd11af00b954e54646b0 6438 golang-github-moby-go-archive_0.3.3-1_amd64.buildinfo
Checksums-Sha256:
a852b795b45d8d55161f7fc2c642ac7262408bfd8aeef85bdb0767c08b56db99 2491 golang-github-moby-go-archive_0.3.3-1.dsc
0b2669026ee52a9ddfafd6189c0886892af7ccf3e4e6f0eed7eaf56109accdc1 98546 golang-github-moby-go-archive_0.3.3.orig.tar.gz
d6c764b058a82040dbc0f48ff18323f4a275ac319ae1adc01ab382351b6e5669 3140 golang-github-moby-go-archive_0.3.3-1.debian.tar.xz
a92a870b6d9a897e5674e9cbe57094e2980d8c6f73f9ad6eb3c43abdf9b926e4 6438 golang-github-moby-go-archive_0.3.3-1_amd64.buildinfo
Files:
b354b693e019641de45373764cf9ba55 2491 golang optional golang-github-moby-go-archive_0.3.3-1.dsc
c3e8c80aec4fc8933416e4127a5e0a7a 98546 golang optional golang-github-moby-go-archive_0.3.3.orig.tar.gz
a41b7ba50e66c37181cc43986f5427d4 3140 golang optional golang-github-moby-go-archive_0.3.3-1.debian.tar.xz
ddac25d7fe1fd25bef97aa39fd580cdb 6438 golang optional golang-github-moby-go-archive_0.3.3-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJGBAEBCgAwFiEE1Bp60H32xfynSJ8cKe7i1uz0QvkFAmqR26gSHGdpYm1hdEBk
ZWJpYW4ub3JnAAoJECnu4tbs9EL5lN8QAJkP+yVT1h85uWlbFQD/SCFw6LyIH1mA
w7JUi6sfsvOA0dNfUZP/PCy6AVxN1c9Z+zZVMVV4FE9shi+JypZx/1vO78il7qEr
ZDh4zt2NMFrhYX1hKdlmLxsqFlt8u9Q1QeMloHE+F4J6tC5wrHo5hnzC29YbQNq+
WllkTHlEm3mWWdnaz0/3M78OLY07kdvxpNwTsNPHSuxPM/mRrvtnK9+4foKd+fWw
VQnaXTLG4FtiFxvz9AmTLUIllbQozc/E3GjBmVOOaKvajvGyLtJiC3OAJuCKBaYZ
DN/J4jDDWvU5A9sXapJCWE/JTyzkquNOeHFKpArvw3s+Esw3LLl+ERlKwDXrJhV5
MhpyfZzRp/i5ezvuhGzYIEGXE6BQfBipAkdkGiEeRf3gyZvw5hmBzIXH2vdX8F5k
c1EbyQolTGC37XLynUXGkI5KUmXjIS26n6b3mKfX+GVAw+mU5NqxCTCZ+I23JyZr
Hn2QvC8SLPc2MZaJL83mPtyM0guZIaRLxs7L4CyaDbmRcvhbp/F2MWw6FIV/wE3x
fNIEb70J83uTa2UWg51rJ6tUSMDydZAntz0BMZQyqzzQSAR0I8XIaJUrpZ4WvlIU
usV5IXR82kdIczln8dBCziIVOzGZV4c6zzQUBcqP2qH0kx5jOwjZeTzb95MyIw4O
YEV7aw6Z7Cyi
=6FmU
-----END PGP SIGNATURE-----