Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-5704
Red Hat Red Hat Enterprise Linux 10 — Tar: tar: hidden file injection via crafted archives
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L N R U N H N 5.5 .0040 32.0 —
AFFECTED
Product Versions Fixed
Red Hat Enterprise Linux 10 unspecified 2:1.35-13.el10_2
Red Hat Enterprise Linux 8 unspecified 2:1.30-13.el8_10
Red Hat Enterprise Linux 9 unspecified 2:1.34-13.el9_8
Red Hat Discovery 2 unspecified 1788205779
Red Hat Hardened Images unspecified 1.35-10.hum1
Red Hat Update Infrastructure 5 unspecified 1788880445
Red Hat Update Infrastructure 5 unspecified 1788880464
Red Hat Update Infrastructure 5 unspecified 1788880456
Red Hat Update Infrastructure 5 unspecified 1788765051
Red Hat Update Infrastructure 5 unspecified 1788880581
+ 2 more
TIMELINE
Apr 6 Reserved by redhat
Apr 6 Published (CNA: redhat)
Aug 31 PATCH SHIPPED — CVE-2026-5704 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 2:1.34-13.el9_8.
Sep 1 EXPLOIT PUBLISHED — CVE-2026-5704 (Red Hat Enterprise Linux 10). Public exploit reference added.
Sep 1 RESCORED — CVE-2026-5704 (Red Hat Enterprise Linux 10). CVSS 5 → 5.5 (NVD).
Sep 10 EXPLOIT PUBLISHED — CVE-2026-5704 (Red Hat Enterprise Linux 10). Public exploit reference added.
Sep 22 EXPLOIT PUBLISHED — CVE-2026-5704 (Red Hat Enterprise Linux 10). Public exploit reference added.
Description
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.
Lifecycle
Complete event history — 7 events, chronological
| Date | Event | Detail |
| April 6, 2026 | Reserved | Reserved by redhat |
| April 6, 2026 | Published | Published (CNA: redhat) |
| August 31, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-5704 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 2:1.34-13.el9_8. |
| September 1, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-5704 (Red Hat Enterprise Linux 10). Public exploit reference added. |
| September 1, 2026 | RESCORED | RESCORED — CVE-2026-5704 (Red Hat Enterprise Linux 10). CVSS 5 → 5.5 (NVD). |
| September 10, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-5704 (Red Hat Enterprise Linux 10). Public exploit reference added. |
| September 22, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-5704 (Red Hat Enterprise Linux 10). Public exploit reference added. |
Affected
Affected products and packages — 12 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | Red Hat Enterprise Linux 10 | — | — | 2:1.35-13.el10_2 |
| Red Hat | Red Hat Enterprise Linux 8 | — | — | 2:1.30-13.el8_10 |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | 2:1.34-13.el9_8 |
| Red Hat | Red Hat Discovery 2 | — | — | 1788205779 |
| Red Hat | Red Hat Hardened Images | — | — | 1.35-10.hum1 |
| Red Hat | Red Hat Update Infrastructure 5 | — | — | 1788880445 |
| Red Hat | Red Hat Update Infrastructure 5 | — | — | 1788880464 |
| Red Hat | Red Hat Update Infrastructure 5 | — | — | 1788880456 |
| Red Hat | Red Hat Update Infrastructure 5 | — | — | 1788765051 |
| Red Hat | Red Hat Update Infrastructure 5 | — | — | 1788880581 |
| Red Hat | Red Hat Enterprise Linux 6 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 7 | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-5704 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.