CVE-2026-18508

EUVD-2026-52327
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.4 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 3.8%
Affected Products (NVD)
VendorProductVersion
gnutar
1.35
redhatopenshift_container_platform
4.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tar
bookworm
postponed
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tar
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
resolute
deferred
trusty
deferred
xenial
deferred
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
tar
RHEL 9
2:1.34-13.el9_8
fixed