CVE-2026-18477

Name
CVE-2026-18477
Description
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
secalert@redhat.com https://access.redhat.com/security/cve/CVE-2026-18477
secalert@redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2509735
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:49361
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:61581
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:61783
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:61586
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:66018

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:tar:1.35:*:*:*:*:*:*:* tar == None == 1.35
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* openshift_container_platform == None == 4.0
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* enterprise_linux == None == 8.0
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* enterprise_linux == None == 9.0
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* enterprise_linux == None == 10.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
tar edge-main 1.35-r5 qaqland <qaq@qaq.land> possibly vulnerable
tar edge-main 1.35-r4 Celeste <cielesti@protonmail.com> possibly vulnerable
tar edge-main 1.35-r3 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
tar edge-main 1.35-r2 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
tar edge-main 1.35-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
tar 3.24-main 1.35-r5 qaqland <qaq@qaq.land> possibly vulnerable
tar 3.23-main 1.35-r4 Celeste <cielesti@protonmail.com> possibly vulnerable
tar 3.22-main 1.35-r3 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
tar 3.21-main 1.35-r2 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
tar 3.20-main 1.35-r2 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
tar 3.19-main 1.35-r2 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable