CVE-2026-18508

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnu:tar:1.35:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-03 16:16

Updated : 2026-09-10 18:17


NVD link : CVE-2026-18508

Mitre link : CVE-2026-18508

CVE.ORG link : CVE-2026-18508


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • openshift_container_platform

gnu

  • tar
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')