Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <fa8031b0-b1fb-4412-ad30-5fb11c3e5752@cs.ucla.edu>
Date: Sun, 12 Apr 2026 09:14:20 -0700
From: Paul Eggert <eggert@...ucla.edu>
To: Collin Funk <collin.funk1@...il.com>, oss-security@...ts.openwall.com
Cc: Vahagn Vardanian <vahagn@...rays.io>
Subject: Re: GNU tar: listing/extraction desynchronization
 allows hidden file injection

On 2026-04-11 21:10, Collin Funk wrote:
> I didn't look much at the others since I am not very familiar with tar.
> Hopefully Paul can quickly tell if they are bogus or not.

Yes, it's on my list of things to look at. As Collin hinted, much of 
that bug report is AI slop and this is why it's low priority for me.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.