File Overwrite Vulnerability in GnuPG's gpgtar Affects GnuPG Software
CVE-2026-105712

3.6LOW

Key Information:

Vendor

Gnupg

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105712?

A file overwrite vulnerability exists in GnuPG's gpgtar utility prior to version 2.5.19. This flaw arises when extracting untrusted archives using the --directory option (-C). If the target directory contains a pre-existing symlink, gpgtar can inadvertently follow that symlink, leading to the creation or overwriting of files outside the intended extraction directory. This risk is particularly significant when the user has sufficient filesystem permissions. To mitigate this vulnerability, it is advised to avoid extracting archives into directories with existing symlinks or to utilize clean, empty directories for extraction.

Affected Version(s)

GnuPG 0 < 2.5.19

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.