ITSECURITYWHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardVulnerabilities › CVE-2026-18508
4.4Medium CVE-2026-18508 Gnu

A flaw was found in GNU tar.

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outsi

What happened

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

Does it affect you

Not enough information

No products recorded, so this cannot be matched against anything.

What to do

  • Follow the vendor advisory for the fixed release and any interim mitigation.
    access.redhat.com
  • Follow the vendor advisory for the fixed release and any interim mitigation.
    access.redhat.com
  • Follow the vendor advisory for the fixed release and any interim mitigation.
    bugzilla.redhat.com

Vendor's affected list

rhel
Exactly 8.0

Sources

A verdict here is derived from what you told us and what the vendor published. It is not an assessment of your environment. Why we never say you are safe.