Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
Published Aug 3, 2026
4.4
MEDIUMCVSS 3.1
EPSS 0.14%
Description
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
|
- 1.35
- 4.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Discovery 2
discovery/discovery-server-rhel9:1788205779
Fixed · RHSA-2026:61783
Red Hat Enterprise Linux 10
tar-2:1.35-13.el10_2
Fixed · RHSA-2026:61586
Red Hat Enterprise Linux 9
tar-2:1.34-13.el9_8
Fixed · RHSA-2026:61581
Red Hat Hardened Images
tar-main-1.35-9.2.hum1
Fixed · RHSA-2026:50807
Red Hat Update Infrastructure 5
rhui5/cds-kubernetes-rhel9:1788880445
Fixed · RHSA-2026:66018
Red Hat Update Infrastructure 5
rhui5/cds-rhel9:1788880464
Fixed · RHSA-2026:66018
Red Hat Update Infrastructure 5
rhui5/haproxy-rhel9:1788880456
Fixed · RHSA-2026:66018
Red Hat Update Infrastructure 5
rhui5/installer-rhel9:1788765051
Fixed · RHSA-2026:66018
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1788880581
Fixed · RHSA-2026:66018
Red Hat Enterprise Linux 6
tar
Out of support scope
Red Hat Enterprise Linux 7
tar
Out of support scope
Red Hat Enterprise Linux 8
tar
Fix deferred
Red Hat Hardened Images
aardvark-dns
Not affected
Red Hat Hardened Images
chunkah
Not affected
Red Hat Hardened Images
grafana12.4
Not affected
Red Hat Hardened Images
grafana13.1
Not affected
Red Hat Hardened Images
netavark
Not affected
Red Hat Hardened Images
nodejs26
Not affected
Red Hat Hardened Images
python-cryptography
Not affected
Red Hat Hardened Images
rust
Not affected
Red Hat Hardened Images
rust-rpm-sequoia
Not affected
Red Hat Hardened Images
yarnpkg
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Discovery 2 | discovery/discovery-server-rhel9:1788205779 | Fixed | RHSA-2026:61783 |
| Red Hat Enterprise Linux 10 | tar-2:1.35-13.el10_2 | Fixed | RHSA-2026:61586 |
| Red Hat Enterprise Linux 9 | tar-2:1.34-13.el9_8 | Fixed | RHSA-2026:61581 |
| Red Hat Hardened Images | tar-main-1.35-9.2.hum1 | Fixed | RHSA-2026:50807 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-rhel9:1788880445 | Fixed | RHSA-2026:66018 |
| Red Hat Update Infrastructure 5 | rhui5/cds-rhel9:1788880464 | Fixed | RHSA-2026:66018 |
| Red Hat Update Infrastructure 5 | rhui5/haproxy-rhel9:1788880456 | Fixed | RHSA-2026:66018 |
| Red Hat Update Infrastructure 5 | rhui5/installer-rhel9:1788765051 | Fixed | RHSA-2026:66018 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1788880581 | Fixed | RHSA-2026:66018 |
| Red Hat Enterprise Linux 6 | tar | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | tar | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | tar | Fix deferred | n/a |
| Red Hat Hardened Images | aardvark-dns | Not affected | n/a |
| Red Hat Hardened Images | chunkah | Not affected | n/a |
| Red Hat Hardened Images | grafana12.4 | Not affected | n/a |
| Red Hat Hardened Images | grafana13.1 | Not affected | n/a |
| Red Hat Hardened Images | netavark | Not affected | n/a |
| Red Hat Hardened Images | nodejs26 | Not affected | n/a |
| Red Hat Hardened Images | python-cryptography | Not affected | n/a |
| Red Hat Hardened Images | rust | Not affected | n/a |
| Red Hat Hardened Images | rust-rpm-sequoia | Not affected | n/a |
| Red Hat Hardened Images | yarnpkg | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Do not use --one-top-level as the sole confinement mechanism when extracting untrusted archives. Prefer extracting as an unprivileged user into a freshly created empty directory after changing into that directory (mkdir and cd), avoid extracting as root from sensitive working directories such as /, and follow the GNU tar security guidance for untrusted archives.
Red Hat statement
Red Hat Enterprise Linux is affected. This issue only applies when the --one-top-level option is used to extract an untrusted archive. Default tar extraction without --one-top-level is not impacted by this specific boundary failure. Users should avoid using --one-top-level as the sole confinement mechanism for untrusted archives until fixed packages are available.
Red Hat mitigation
Do not use --one-top-level as the sole confinement mechanism when extracting untrusted archives. Prefer extracting as an unprivileged user into a freshly created empty directory after changing into that directory (mkdir and cd), avoid extracting as root from sensitive working directories such as /, and follow the GNU tar security guidance for untrusted archives.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 3, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.14% (0.00141) | 2.86th | v5 (v2026.06.15) |
| Aug 4, 2026 | 0.13% (0.00131) | 3.12th | v5 (v2026.06.15) |
References (10)
- https://access.redhat.com/errata/RHSA-2026:50807 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2026:61581 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:61586 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:61783 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:66018 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:70390 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-18508 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2509843 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-18508
- https://www.cve.org/CVERecord?id=CVE-2026-18508
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:50807 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/errata/RHSA-2026:61581 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:61586 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:61783 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:66018 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:70390 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-18508 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2509843 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-18508 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-18508 |
Change history (0)
No recorded changes yet.