A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated… (CVE-2026-18508)
A vulnerability in GNU tar allows hardlink targets created during extraction with the --one-top-level option to escape the designated top-level directory. This can enable writing outside the intended extraction boundary if combined with a preexisting symbolic link in the working directory. The issue only affects extraction using --one-top-level and does not impact default tar extraction. The vulnerability has a moderate severity score of 4.4 CVSS and requires user interaction with local access.
AI Analysis
Technical Summary
CVE-2026-18508 is a vulnerability in GNU tar where, when extracting an archive using the --one-top-level option, hardlink targets are not properly confined to the specified top-level directory. Instead, these hardlinks may resolve relative to the extraction working directory, allowing crafted archives to create hardlinks that escape the intended extraction boundary. If a preexisting symbolic link exists under the working directory, this can lead to writing files outside the intended directory during a single extraction operation. This flaw is classified under CWE-59 (Improper Link Resolution Before File Access). The vulnerability has a CVSS v3.1 score of 4.4 (medium severity) with local attack vector, low attack complexity, no privileges required, user interaction required, and low confidentiality and integrity impact. The issue affects Red Hat Enterprise Linux when using the --one-top-level option with untrusted archives. Default extraction without this option is not affected. No official patch or fixed version is currently provided in the advisory.
Potential Impact
An attacker who can supply a crafted archive and cause it to be extracted with the --one-top-level option may be able to write files outside the intended extraction directory if a symbolic link exists in the working directory. This can lead to unauthorized modification of files outside the target directory, potentially bypassing file system boundaries and security mechanisms. The confidentiality and integrity impacts are low, and availability is not affected. The attack requires local access and user interaction to extract the archive.
Mitigation Recommendations
Do not rely solely on the --one-top-level option to confine extraction of untrusted archives. Instead, extract archives as an unprivileged user into a freshly created empty directory after changing into that directory (using mkdir and cd). Avoid extracting as root from sensitive directories such as /. Follow GNU tar security guidance for handling untrusted archives. Currently, no fixed packages are available, so these mitigations are necessary until a patch is released.
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated… (CVE-2026-18508)
Description
A vulnerability in GNU tar allows hardlink targets created during extraction with the --one-top-level option to escape the designated top-level directory. This can enable writing outside the intended extraction boundary if combined with a preexisting symbolic link in the working directory. The issue only affects extraction using --one-top-level and does not impact default tar extraction. The vulnerability has a moderate severity score of 4.4 CVSS and requires user interaction with local access.
CVSS v3.1
Score 4.4medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-18508 is a vulnerability in GNU tar where, when extracting an archive using the --one-top-level option, hardlink targets are not properly confined to the specified top-level directory. Instead, these hardlinks may resolve relative to the extraction working directory, allowing crafted archives to create hardlinks that escape the intended extraction boundary. If a preexisting symbolic link exists under the working directory, this can lead to writing files outside the intended directory during a single extraction operation. This flaw is classified under CWE-59 (Improper Link Resolution Before File Access). The vulnerability has a CVSS v3.1 score of 4.4 (medium severity) with local attack vector, low attack complexity, no privileges required, user interaction required, and low confidentiality and integrity impact. The issue affects Red Hat Enterprise Linux when using the --one-top-level option with untrusted archives. Default extraction without this option is not affected. No official patch or fixed version is currently provided in the advisory.
Potential Impact
An attacker who can supply a crafted archive and cause it to be extracted with the --one-top-level option may be able to write files outside the intended extraction directory if a symbolic link exists in the working directory. This can lead to unauthorized modification of files outside the target directory, potentially bypassing file system boundaries and security mechanisms. The confidentiality and integrity impacts are low, and availability is not affected. The attack requires local access and user interaction to extract the archive.
Mitigation Recommendations
Do not rely solely on the --one-top-level option to confine extraction of untrusted archives. Instead, extract archives as an unprivileged user into a freshly created empty directory after changing into that directory (using mkdir and cd). Avoid extracting as root from sensitive directories such as /. Follow GNU tar security guidance for handling untrusted archives. Currently, no fixed packages are available, so these mitigations are necessary until a patch is released.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-4f5j-wqjr-hx49
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-18508"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a710659bf32cb7a3439375d
Added to database: 08/03/2026, 21:21:29 UTC
Last enriched: 08/03/2026, 21:28:09 UTC
Last updated: 08/04/2026, 03:17:47 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.