Vulnerability in Buildah/Copy Package Allows Unauthorized File Creation by Non-Root Users
CVE-2026-79705

4.5MEDIUM

What is CVE-2026-79705?

A flaw exists in the Buildah/copier Go package that can be exploited when it's used outside of Buildah by non-root users. This vulnerability arises when handling crafted tar archives containing malicious symbolic links. Such archives can potentially bypass the intended extraction directory, allowing files to be created outside the target destination, thereby leading to unauthorized access and manipulation of the filesystem.

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Ibrahim Saglam, Junyi Liu, Oleh Konko, and Ron Masas for reporting this issue.
.