Vulnerability in GNU tar Affects Hardlink Handling
CVE-2026-18508
4.4MEDIUM
What is CVE-2026-18508?
A vulnerability has been identified in GNU tar related to the extraction of archives using the --one-top-level option. This flaw allows hardlink targets to escape the intended directory constraints, resulting in potential manipulation of file system boundaries. When an archive is extracted, crafted links can lead to unauthorized interactions with the file system, especially when existing symbolic links are present in the working directory. This behavior may pose significant security risks, allowing malicious users to write files outside designated areas during the extraction process.
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Pavel Cahyna (Red Hat).