Vulnerability in GNU tar Affects Hardlink Handling
CVE-2026-18508
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 3 August 2026
What is CVE-2026-18508?
A vulnerability has been identified in GNU tar related to the extraction of archives using the --one-top-level option. This flaw allows hardlink targets to escape the intended directory constraints, resulting in potential manipulation of file system boundaries. When an archive is extracted, crafted links can lead to unauthorized interactions with the file system, especially when existing symbolic links are present in the working directory. This behavior may pose significant security risks, allowing malicious users to write files outside designated areas during the extraction process.
Affected Version(s)
Red Hat Discovery 2 1788205779
Red Hat Enterprise Linux 10 2:1.35-13.el10_2
Red Hat Enterprise Linux 9 2:1.34-13.el9_8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved