Back

HIGH

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory

Published May 26, 2026

Description

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.

_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.

A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.

Affected products

Remediation

Vendor solution

Upgrade to Archive::Tar 3.08 or later.

Red Hat statement

This Moderate impact vulnerability in `perl-Archive-Tar` allows an attacker to modify arbitrary files on the system. By crafting a malicious tar archive, an attacker can exploit a path traversal flaw during extraction to create hardlinks outside the intended directory. This could lead to data corruption or unauthorized changes to sensitive system files if a user extracts a specially crafted archive.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner CPANSec
Published May 26, 2026
Updated May 28, 2026
Reserved Apr 27, 2026

CISA Vulnrichment

Updated May 28, 2026

NVD

Status Modified
Modified Jul 24, 2026

Red Hat

Severity Moderate
Public date May 26, 2026
Bugzilla 2481317

ENISA EUVD

Assigner CPANSec
Published May 26, 2026
Updated May 28, 2026

GitHub

No data