CVE Vulnerabilities

CVE-2026-18508

Improper Link Resolution Before File Access ('Link Following')

Published: Aug 03, 2026 | Modified: Sep 22, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
4.4 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in GNU tar. When extracting an archive with the –one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

Weakness

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Affected Software

NameVendorStart VersionEnd Version
TarGnu1.35 (including)1.35 (including)
Openshift_container_platformRedhat4.0 (including)4.0 (including)
Enterprise_linuxRedhat8.0 (including)8.0 (including)
Enterprise_linuxRedhat9.0 (including)9.0 (including)
Enterprise_linuxRedhat10.0 (including)10.0 (including)
Red Hat Enterprise Linux 10RedHattar-2:1.35-13.el10_2*
Red Hat Enterprise Linux 8RedHattar-2:1.30-13.el8_10*
Red Hat Enterprise Linux 9RedHattar-2:1.34-13.el9_8*
Red Hat Discovery 2RedHatdiscovery/discovery-server-rhel9:1788205779*
Red Hat Hardened ImagesRedHattar-main-1.35-9.2.hum1*
Red Hat Update Infrastructure 5RedHatrhui5/cds-kubernetes-rhel9:1788880445*
Red Hat Update Infrastructure 5RedHatrhui5/cds-rhel9:1788880464*
Red Hat Update Infrastructure 5RedHatrhui5/haproxy-rhel9:1788880456*
Red Hat Update Infrastructure 5RedHatrhui5/installer-rhel9:1788765051*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:1788880581*
TarUbuntudevel*
TarUbuntuesm-infra-legacy/trusty*
TarUbuntuesm-infra-legacy/xenial*
TarUbuntuesm-infra/bionic*
TarUbuntuesm-infra/focal*
TarUbuntujammy*
TarUbuntunoble*
TarUbunturesolute*

Potential Mitigations

  • Follow the principle of least privilege when assigning access rights to entities in a software system.
  • Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.

References