Description
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Affected products
- gnu / Tar1.35 – 1.35
- RedHat / enterprise_linux8.0 – 8.0
- RedHat / enterprise_linux9.0 – 9.0
- RedHat / enterprise_linux10.0 – 10.0
- RedHat / openshift_container_platform4.0 – 4.0
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:50807
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:61581
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:61586
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:61783
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:66018
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2026-18508
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2509843
Updated 19m ago · 8 sources