Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.4epss 0.1%
exploitation probability
0.1%top 96% of all CVEs
observed exploitation
nono source reports it
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected products
Red Hat · Red Hat Discovery 2Red Hat · Red Hat Enterprise Linux 10Red Hat · Red Hat Enterprise Linux 6Red Hat · Red Hat Enterprise Linux 7Red Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 9Red Hat · Red Hat Hardened ImagesRed Hat · Red Hat OpenShift Container Platform 4Red Hat · Red Hat Update Infrastructure 5References
https://access.redhat.com/errata/RHSA-2026:50807https://access.redhat.com/errata/RHSA-2026:61581https://access.redhat.com/errata/RHSA-2026:61586https://access.redhat.com/errata/RHSA-2026:61783https://access.redhat.com/errata/RHSA-2026:66018https://access.redhat.com/errata/RHSA-2026:70390https://access.redhat.com/security/cve/CVE-2026-18508https://bugzilla.redhat.com/show_bug.cgi?id=2509843