Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-7774

Опубликовано: 04 июн. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.

РелизСтатусПримечание
devel

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

jammy

needs-triage

noble

needs-triage

questing

ignored

end of life, was needs-triage
resolute

needs-triage

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

not-affected

see notes
esm-apps/jammy

not-affected

see notes
esm-infra-legacy/trusty

not-affected

see notes
esm-infra-legacy/xenial

not-affected

see notes
esm-infra/bionic

not-affected

see notes
jammy

not-affected

see notes
noble

DNE

questing

DNE

resolute

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

not-affected

see notes
noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

see notes

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/jammy

not-affected

see notes
jammy

not-affected

see notes
noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

see notes

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

released

3.12.3-1ubuntu0.15
questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

DNE

questing

ignored

end of life, was needs-triage
resolute

DNE

upstream

released

3.13.14-1

Показывать по

РелизСтатусПримечание
devel

not-affected

3.14.6-1
jammy

DNE

noble

DNE

questing

ignored

end of life, was needs-triage
resolute

released

3.14.4-1ubuntu0.1
upstream

released

3.14.6

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

not-affected

see notes
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

see notes

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

not-affected

see notes
esm-infra-legacy/xenial

not-affected

see notes
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

see notes

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

not-affected

see notes
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

see notes

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

not-affected

see notes
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

see notes

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

not-affected

see notes
esm-infra/focal

not-affected

see notes
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

see notes

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

not-affected

see notes
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

see notes

Показывать по

EPSS

Процентиль: 45%
0.00606
Низкий

Связанные уязвимости

CVSS3: 6.5
redhat
около 2 месяцев назад

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.

nvd
около 2 месяцев назад

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.

msrc
около 2 месяцев назад

tarfile.data_filter path traversal bypass allows writing outside the extraction directory

debian
около 2 месяцев назад

tarfile.data_filter could be bypassed using crafted link entries, incl ...

github
около 2 месяцев назад

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.

EPSS

Процентиль: 45%
0.00606
Низкий
Уязвимость CVE-2026-7774