← Back

CVE-2026-18508

nvd nist
Published: Aug 3, 2026Modified: Sep 1, 2026

JSON object

Loading...
4.4
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Exploitability: 1.8 / Impact: 2.5
Source: secalert@redhat.com (Secondary)

Description

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

Affected (5)

1 product
Tar
2 products
Enterprise Linux
Openshift Container Platform
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.35
Redhat
Version 10.0
Version 8.0
Version 9.0
Version 4.0

References (6)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue TrackingVendor Advisory

Timeline

No history available yet.