CVE-2026-79655

EUVD-2026-65492
A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issue during tar extraction, where symlink and hardlink targets are not properly validated. This enables the attacker to write files to arbitrary locations on the system with the privileges of the sos clean process, which often runs as root.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 10.78%
Debian logo
Debian Releases
Debian Product
Codename
sos
forky
4.12.0-2
fixed
sid
4.12.0-2
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sos
jammy
dne
noble
dne
resolute
needs-triage
sosreport
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
resolute
dne
trusty
deferred
xenial
deferred
Azure Linux logo
Azure Linux Releases
Azure Package
Release
sos
Azure Linux 3.0
0:4.6.1-3.azl3
fixed