Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-7774

Опубликовано: 04 июн. 2026
Источник: redhat
CVSS3: 6.5

Описание

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.

A flaw was found in the tarfile.data_filter function within the Python tarfile module. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive containing malicious link entries, such as symlinks with empty or directory-like names. This bypass allows the attacker to redirect subsequent archive members outside the intended extraction directory, leading to arbitrary file writes on the system where the archive is extracted. The impact of this flaw is limited by the permissions of the extracting process.

Отчет

This flaw is rated as Moderate. The CPython tarfile module is susceptible to arbitrary file writes when processing a specially crafted archive containing malicious link entries. Exploitation requires user interaction to extract the archive, and the impact is constrained by the permissions of the extracting process, limiting the scope of potential data integrity compromise.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8python36Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2484827python: CPython: Python tarfile: Arbitrary file write via crafted link entries

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
около 2 месяцев назад

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.

nvd
около 2 месяцев назад

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.

msrc
около 2 месяцев назад

tarfile.data_filter path traversal bypass allows writing outside the extraction directory

debian
около 2 месяцев назад

tarfile.data_filter could be bypassed using crafted link entries, incl ...

github
около 2 месяцев назад

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.

6.5 Medium

CVSS3