Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.1epss 0.4%
exploitation probability
0.4%top 65% of all CVEs
observed exploitation
nono source reports it
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.
_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.
A subsequent open through the extracted name reads or writes the attacker chosen path.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
BINGOS · Archive::TarReferences
https://access.redhat.com/errata/RHSA-2026:30851https://access.redhat.com/errata/RHSA-2026:30852https://access.redhat.com/errata/RHSA-2026:30856https://access.redhat.com/errata/RHSA-2026:30857https://access.redhat.com/security/cve/CVE-2026-42496https://bugzilla.redhat.com/show_bug.cgi?id=2481314https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patchhttps://metacpan.org/release/BINGOS/Archive-Tar-3.08/changeshttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.jsonhttps://www.cve.org/CVERecord?id=CVE-2026-42497