Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42497

Опубликовано: 26 мая 2026
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode. A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.

A flaw was found in perl-Archive-Tar. This vulnerability allows an attacker to craft a malicious tar archive that, when extracted, can create hardlinks to arbitrary files outside the intended extraction directory. This could lead to the modification of sensitive files on the system, potentially resulting in data corruption or unauthorized access.

Отчет

This Moderate impact vulnerability in perl-Archive-Tar allows an attacker to modify arbitrary files on the system. By crafting a malicious tar archive, an attacker can exploit a path traversal flaw during extraction to create hardlinks outside the intended directory. This could lead to data corruption or unauthorized changes to sensitive system files if a user extracts a specially crafted archive.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10perl-Archive-TarFix deferred
Red Hat Enterprise Linux 7perl-Archive-TarOut of support scope
Red Hat Enterprise Linux 8perl:5.32/perl-Archive-TarFix deferred
Red Hat Enterprise Linux 8perl-Archive-TarFix deferred
Red Hat Enterprise Linux 9perl-Archive-TarFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2481317perl-Archive-Tar: perl-Archive-Tar: Arbitrary file modification via crafted hardlinks during archive extraction

EPSS

Процентиль: 34%
0.00417
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode. A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.

CVSS3: 7.5
nvd
2 месяца назад

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode. A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.

msrc
2 месяца назад

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory

CVSS3: 7.5
debian
2 месяца назад

Archive::Tar versions before 3.08 for Perl extract hardlinks to attack ...

CVSS3: 7.5
github
2 месяца назад

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode. A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.

EPSS

Процентиль: 34%
0.00417
Низкий

6.8 Medium

CVSS3