GNU tar flaw allows bypassing security measures
Dell Secure Connect Gateway has a CERT-Bund advisory for CVE-2026-5704 in versions before 5.36.00.16. A local attacker can exploit a vulnerability in GNU tar to bypass security measures.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Fixed in 5.36.00.16Fix recorded 3 days ago
- Affected versions
- before 5.36.00.16
- Affects
- Dell Secure Connect Gateway+3 more
- Exploited
- Not confirmedNo confirmation recorded
How it works
A local attacker can exploit a vulnerability in GNU tar to bypass security measures.
What to do
Check your Dell Secure Connect Gateway version. If it is before 5.36.00.16, this advisory applies.
Update Dell Secure Connect Gateway to 5.36.00.16 or newer.
Technical details
Affected software: Dell Secure Connect Gateway, Linux, UNIX, Windows
A local attacker can exploit a vulnerability in GNU tar to bypass security measures. The advisory tracks CVE-2026-5704. In CERT-Bund's CSAF data, affected versions are before 5.36.00.16, and the fixed version is 5.36.00.16. Affected operating systems listed by CERT-Bund: Linux, UNIX, Windows.
References
- wid.cert-bund.de · wid-sec-w-2026-1057.json technical description
- nvd.nist.gov · CVE-2026-5704 third party advisory
- seclists.org · 104 third party advisory
- bugzilla.redhat.com · show_bug.cgi third party advisory
- ubuntu.com · USN-8477-1 third party advisory
- lists.opensuse.org · MEVZDBXI7TJLVUUWDHDN3SBKJFWWBICQ third party advisory
- lists.suse.com · 027036.html third party advisory
- lists.opensuse.org · MZEM7I7VWBK6BZVQH4CS7YJRILST7V7F third party advisory
- lists.suse.com · 027076.html third party advisory
- lists.suse.com · 027113.html third party advisory
- ubuntu.com · USN-8477-2 third party advisory
- ubuntu.com · USN-8477-3 third party advisory
- dell.com · dsa-2026-386-security-update-f third party advisory
- errata.build.resf.org · RLSA-2026:61581 third party advisory
- access.redhat.com · RHSA-2026:61783 third party advisory
- dell.com · dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities third party advisory
- access.redhat.com · RHSA-2026:61586 third party advisory
- linux.oracle.com · ELSA-2026-61581-0.html third party advisory
- linux.oracle.com · ELSA-2026-61586-0.html third party advisory
- bodhi.fedoraproject.org · FEDORA-2026-044e56d9ff third party advisory
- bodhi.fedoraproject.org · FEDORA-2026-ee1eb89e7b third party advisory
- errata.build.resf.org · RLSA-2026:61586 third party advisory
- access.redhat.com · RHSA-2026:66514 third party advisory