Skip to content

Advisories for the tar issues announced last week#2737

Merged
djc merged 1 commit intorustsec:mainfrom
LawnGnome:tar-rs-2026
Mar 23, 2026
Merged

Advisories for the tar issues announced last week#2737
djc merged 1 commit intorustsec:mainfrom
LawnGnome:tar-rs-2026

Conversation

@LawnGnome
Copy link
Contributor

This is the first time I've created full-blown RustSec advisories for things other than malicious crates, so I've almost certainly fucked something up.

Text for all three advisories is derived from the PD CVE entries and lightly edited to make it fit in RustSec.

I chose to only include affected functions for the chmod issue because it's more tightly focused than the other PAX header issues, which basically affect any usage of the crates.

@LawnGnome LawnGnome added the advisory security advisory PRs label Mar 22, 2026
@djc
Copy link
Member

djc commented Mar 23, 2026

@konstin are you okay with us publishing this advisory?

@cgwalters how about you?

Copy link
Contributor

@woodruffw woodruffw left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks right to me for astral-tokio-tar, thanks @LawnGnome and @djc!

(I'm the responsible party for this one at Astral, not @konstin 🙂)

@djc
Copy link
Member

djc commented Mar 23, 2026

Might want to get yourself listed as a maintainer on crates.io. 👍

@djc
Copy link
Member

djc commented Mar 23, 2026

Thanks for the quick responses!

@djc djc merged commit 143986b into rustsec:main Mar 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

advisory security advisory PRs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants