Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18508

Опубликовано: 31 июл. 2026
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

Отчет

Red Hat Enterprise Linux is affected. This issue only applies when the --one-top-level option is used to extract an untrusted archive. Default tar extraction without --one-top-level is not impacted by this specific boundary failure. Users should avoid using --one-top-level as the sole confinement mechanism for untrusted archives until fixed packages are available.

Меры по смягчению последствий

Do not use --one-top-level as the sole confinement mechanism when extracting untrusted archives. Prefer extracting as an unprivileged user into a freshly created empty directory after changing into that directory (mkdir and cd), avoid extracting as root from sensitive working directories such as /, and follow the GNU tar security guidance for untrusted archives.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tarAffected
Red Hat Enterprise Linux 6tarOut of support scope
Red Hat Enterprise Linux 7tarOut of support scope
Red Hat Enterprise Linux 8tarFix deferred
Red Hat Enterprise Linux 9tarFix deferred
Red Hat Hardened Imagesaardvark-dnsNot affected
Red Hat Hardened ImageschunkahNot affected
Red Hat Hardened Imagesgrafana12.4Not affected
Red Hat Hardened Imagesgrafana13.1Not affected
Red Hat Hardened ImagesnetavarkNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2509843tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite

EPSS

Процентиль: 4%
0.00137
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
ubuntu
7 дней назад

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

CVSS3: 4.4
nvd
7 дней назад

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

msrc
3 дня назад

Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite

CVSS3: 4.4
debian
7 дней назад

A flaw was found in GNU tar. When extracting an archive with the --one ...

CVSS3: 4.4
github
7 дней назад

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

EPSS

Процентиль: 4%
0.00137
Низкий

4.4 Medium

CVSS3