CVE-2026-18508

Name
CVE-2026-18508
Description
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
secalert@redhat.com https://access.redhat.com/security/cve/CVE-2026-18508
secalert@redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2509843
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:50807
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:61581
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:61783
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:61586
secalert@redhat.com https://access.redhat.com/errata/RHSA-2026:66018

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:tar:1.35:*:*:*:*:*:*:* tar == None == 1.35
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* openshift_container_platform == None == 4.0
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* enterprise_linux == None == 8.0
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* enterprise_linux == None == 9.0
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* enterprise_linux == None == 10.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
tar edge-main 1.35-r5 qaqland <qaq@qaq.land> possibly vulnerable
tar edge-main 1.35-r4 Celeste <cielesti@protonmail.com> possibly vulnerable
tar edge-main 1.35-r3 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
tar edge-main 1.35-r2 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
tar edge-main 1.35-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
tar 3.24-main 1.35-r5 qaqland <qaq@qaq.land> possibly vulnerable
tar 3.23-main 1.35-r4 Celeste <cielesti@protonmail.com> possibly vulnerable
tar 3.22-main 1.35-r3 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
tar 3.21-main 1.35-r2 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
tar 3.20-main 1.35-r2 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
tar 3.19-main 1.35-r2 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable