GNU tar Hardlink Extraction Path Traversal via --one-top-level
CVE-2026-18508 Published on August 3, 2026
Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
Vulnerability Analysis
CVE-2026-18508 is exploitable with local system access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an insecure temporary file Vulnerability?
The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVE-2026-18508 has been classified to as an insecure temporary file vulnerability or weakness.
Products Associated with CVE-2026-18508
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
Red Hat Enterprise Linux 10:- Version 2:1.35-13.el10_2 and below * is unaffected.
- Version 2:1.34-13.el9_8 and below * is unaffected.
- Version 1788205779 and below * is unaffected.
- Version 1.35-9.2.hum1 and below * is unaffected.
- Version 1788880445 and below * is unaffected.
- Version 1788880464 and below * is unaffected.
- Version 1788880456 and below * is unaffected.
- Version 1788765051 and below * is unaffected.
- Version 1788880581 and below * is unaffected.