Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18477

Опубликовано: 31 июл. 2026
Источник: redhat
CVSS3: 4.4

Описание

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.

Отчет

This issue affects GNU tar incremental backup and restore (-g/-G). A local attacker who can write to content included in an incremental backup, and who can also access the system where that backup is later restored, may cause the restore to create, rename, or overwrite paths outside the intended extraction directory via a TOCTOU race in dumpdir 'X' handling. The attacker does not need to craft or alter the archive, and extracting it into a fresh directory does not mitigate the issue. Red Hat is assessing impact for the tar package in supported products.

Меры по смягчению последствий

Do not perform incremental restores (-G/-g) from untrusted archives. Avoid restoring incremental backups on systems where untrusted users have shell access,​ perform restoration only on systems inaccessible to users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tarAffected
Red Hat Enterprise Linux 6tarOut of support scope
Red Hat Enterprise Linux 7tarOut of support scope
Red Hat Enterprise Linux 8tarAffected
Red Hat Enterprise Linux 9tarAffected
Red Hat Hardened Imagesaardvark-dnsNot affected
Red Hat Hardened ImageschunkahNot affected
Red Hat Hardened Imagesgrafana12.4Not affected
Red Hat Hardened Imagesgrafana13.1Not affected
Red Hat Hardened ImagesnetavarkNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=2509735tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
ubuntu
7 дней назад

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.

CVSS3: 4.4
nvd
7 дней назад

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.

msrc
3 дня назад

Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape

CVSS3: 4.4
debian
7 дней назад

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's increm ...

CVSS3: 4.4
github
7 дней назад

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.

4.4 Medium

CVSS3