{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/oraclelinux6els/vex/2026/cve-2026-53655-els_os-oraclelinux6els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-06-29T12:53:11Z",
      "generator": {
        "date": "2026-06-29T12:53:11Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-53655-ELS_OS-ORACLELINUX6ELS",
      "initial_release_date": "2026-06-22T16:16:00Z",
      "revision_history": [
        {
          "date": "2026-06-22T16:16:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-27T12:30:08Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-06-29T12:53:11Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-53655"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Oracle Linux 6",
                "product": {
                  "name": "Oracle Linux 6",
                  "product_id": "Oracle-Linux-6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Oracle Linux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "tar-2:1.23-15.el6_8.x86_64",
                "product": {
                  "name": "tar-2:1.23-15.el6_8.x86_64",
                  "product_id": "tar-2:1.23-15.el6_8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/tar@1.23-15.el6_8?arch=x86_64&epoch=2"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Oracle Corporation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "tar-2:1.23-15.el6_8.tuxcare.els1.x86_64",
                "product": {
                  "name": "tar-2:1.23-15.el6_8.tuxcare.els1.x86_64",
                  "product_id": "tar-2:1.23-15.el6_8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/tar@1.23-15.el6_8.tuxcare.els1?arch=x86_64&epoch=2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "tar-2:1.23-15.el6_8.tuxcare.els2.x86_64",
                "product": {
                  "name": "tar-2:1.23-15.el6_8.tuxcare.els2.x86_64",
                  "product_id": "tar-2:1.23-15.el6_8.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/tar@1.23-15.el6_8.tuxcare.els2?arch=x86_64&epoch=2"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-2:1.23-15.el6_8.tuxcare.els1.x86_64 as a component of Oracle Linux 6",
          "product_id": "Oracle-Linux-6:tar-2:1.23-15.el6_8.tuxcare.els1.x86_64"
        },
        "product_reference": "tar-2:1.23-15.el6_8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Oracle-Linux-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-2:1.23-15.el6_8.tuxcare.els2.x86_64 as a component of Oracle Linux 6",
          "product_id": "Oracle-Linux-6:tar-2:1.23-15.el6_8.tuxcare.els2.x86_64"
        },
        "product_reference": "tar-2:1.23-15.el6_8.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Oracle-Linux-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-2:1.23-15.el6_8.x86_64 as a component of Oracle Linux 6",
          "product_id": "Oracle-Linux-6:tar-2:1.23-15.el6_8.x86_64"
        },
        "product_reference": "tar-2:1.23-15.el6_8.x86_64",
        "relates_to_product_reference": "Oracle-Linux-6"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-53655",
      "cwe": {
        "id": "CWE-436",
        "name": "Interpretation Conflict"
      },
      "notes": [
        {
          "category": "description",
          "text": "node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a PAX extended header (x) describes the next file entry, not the intermediary extension headers that may sit between the x header and the file it annotates. Because node-tar lets the PAX size override the byte length of an intervening L/K/x header, an attacker can desynchronize node-tar's stream cursor relative to every other mainstream tar implementation (GNU tar, libarchive/bsdtar, Python tarfile, and the now-fixed tar-rs / astral-tokio-tar). The result is a tar parser interpretation differential (CWE-436): a single crafted archive yields a different set of members under node-tar than under the reference tar tools. An attacker can use this to hide a member from one parser while it is visible to another, which defeats security tooling whose scanner and extractor disagree on archive contents (e.g. a malware/secret scanner that lists entries with one library while a downstream step extracts with another) This vulnerability is fixed in 7.5.16.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Oracle-Linux-6:tar-2:1.23-15.el6_8.tuxcare.els1.x86_64",
          "Oracle-Linux-6:tar-2:1.23-15.el6_8.tuxcare.els2.x86_64",
          "Oracle-Linux-6:tar-2:1.23-15.el6_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-53655"
        },
        {
          "category": "external",
          "summary": "https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh",
          "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh"
        }
      ],
      "release_date": "2026-06-22T16:16:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-06-29T11:27:16.665896Z",
          "details": "This issue is a local, user‑interaction parsing differential in node‑tar before 7.5.16 that only becomes relevant when a crafted archive is scanned/listed with one tar implementation but actually extracted with vulnerable node‑tar, producing mismatched file listings. It does not yield code execution or privilege escalation and has no confidentiality or availability impact; the effect is limited to integrity in mixed‑tool workflows processing untrusted archives. In enterprise VM/server contexts that use a single extractor for both scanning and extraction or do not automatically unpack untrusted inputs with node‑tar, the practical exploitability is low and the CVE can be safely deprioritized.",
          "product_ids": [
            "Oracle-Linux-6:tar-2:1.23-15.el6_8.tuxcare.els1.x86_64",
            "Oracle-Linux-6:tar-2:1.23-15.el6_8.tuxcare.els2.x86_64",
            "Oracle-Linux-6:tar-2:1.23-15.el6_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "Oracle-Linux-6:tar-2:1.23-15.el6_8.tuxcare.els1.x86_64",
            "Oracle-Linux-6:tar-2:1.23-15.el6_8.tuxcare.els2.x86_64",
            "Oracle-Linux-6:tar-2:1.23-15.el6_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}