CVE Vulnerabilities

CVE-2026-17106

Improper Link Resolution Before File Access ('Link Following')

Published: Aug 18, 2026 | Modified: Aug 28, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process.

Weakness

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatpodman-7:5.8.2-9.el10_2*
Red Hat Enterprise Linux 10RedHatrhel10/podman:7:5.8.2-9.el10_2*
Red Hat Enterprise Linux 10RedHatubi10/podman:7:5.8.2-9.el10_2*
Red Hat Enterprise Linux 9RedHatpodman-6:5.8.2-7.el9_8*
Logging Subsystem for Red Hat OpenShift 6.6RedHatopenshift-logging/cluster-logging-rhel9-operator:1788439505*
Multicluster Global Hub 1.8.2RedHatmulticluster-globalhub/multicluster-globalhub-grafana-rhel9:1788441983*
Multicluster Global Hub 1.8.2RedHatmulticluster-globalhub/multicluster-globalhub-grafana-rhel9:1790639009*
Red Hat Advanced Cluster Management for Kubernetes 2.17RedHatrhacm2/acm-grafana-rhel9:1790240693*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-alert-exporter-rhel10:1789485358*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-alertmanager-proxy-rhel10:1789485956*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-api-rhel10:1789485653*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-cli-artifacts-rhel10:1789486382*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-db-setup-rhel10:1789487147*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-imagebuilder-api-rhel10:1789485823*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-imagebuilder-worker-rhel10:1789485526*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-pam-issuer-rhel10:1789487060*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-periodic-rhel10:1789486651*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-telemetry-gateway-rhel10:1789486468*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-userinfo-proxy-rhel10:1789486659*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-worker-rhel10:1789486740*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-alert-exporter-rhel9:1789485374*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-alertmanager-proxy-rhel9:1789486471*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-api-rhel9:1789485317*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-cli-artifacts-rhel9:1789485390*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-db-setup-rhel9:1789485698*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-imagebuilder-api-rhel9:1789485260*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-imagebuilder-worker-rhel9:1789487407*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-pam-issuer-rhel9:1789487540*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-periodic-rhel9:1789485282*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-telemetry-gateway-rhel9:1789486233*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-userinfo-proxy-rhel9:1789485510*
Red Hat Edge Manager 1.2RedHatrhem/flightctl-worker-rhel9:1789488061*
Red Hat Hardened ImagesRedHatpodman-main-6.0.2-2.2.hum1*

Potential Mitigations

  • Follow the principle of least privilege when assigning access rights to entities in a software system.
  • Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.

References