File Overwrite Vulnerability in GnuPG's gpgtar Affects GnuPG Software
CVE-2026-105712
3.6LOW
What is CVE-2026-105712?
A file overwrite vulnerability exists in GnuPG's gpgtar utility prior to version 2.5.19. This flaw arises when extracting untrusted archives using the --directory option (-C). If the target directory contains a pre-existing symlink, gpgtar can inadvertently follow that symlink, leading to the creation or overwriting of files outside the intended extraction directory. This risk is particularly significant when the user has sufficient filesystem permissions. To mitigate this vulnerability, it is advised to avoid extracting archives into directories with existing symlinks or to utilize clean, empty directories for extraction.
Affected Version(s)
GnuPG 0 < 2.5.19
