Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated… (CVE-2026-18508)

0
Medium
Published: 08/03/2026 (08/03/2026, 18:30:45 UTC)
Source: GCVE Database

Description

A vulnerability in GNU tar allows hardlink targets created during extraction with the --one-top-level option to escape the designated top-level directory. This can enable writing outside the intended extraction boundary if combined with a preexisting symbolic link in the working directory. The issue only affects extraction using --one-top-level and does not impact default tar extraction. The vulnerability has a moderate severity score of 4.4 CVSS and requires user interaction with local access.

CVSS v3.1

Score 4.4medium

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/03/2026, 21:28:09 UTC

Technical Analysis

CVE-2026-18508 is a vulnerability in GNU tar where, when extracting an archive using the --one-top-level option, hardlink targets are not properly confined to the specified top-level directory. Instead, these hardlinks may resolve relative to the extraction working directory, allowing crafted archives to create hardlinks that escape the intended extraction boundary. If a preexisting symbolic link exists under the working directory, this can lead to writing files outside the intended directory during a single extraction operation. This flaw is classified under CWE-59 (Improper Link Resolution Before File Access). The vulnerability has a CVSS v3.1 score of 4.4 (medium severity) with local attack vector, low attack complexity, no privileges required, user interaction required, and low confidentiality and integrity impact. The issue affects Red Hat Enterprise Linux when using the --one-top-level option with untrusted archives. Default extraction without this option is not affected. No official patch or fixed version is currently provided in the advisory.

Potential Impact

An attacker who can supply a crafted archive and cause it to be extracted with the --one-top-level option may be able to write files outside the intended extraction directory if a symbolic link exists in the working directory. This can lead to unauthorized modification of files outside the target directory, potentially bypassing file system boundaries and security mechanisms. The confidentiality and integrity impacts are low, and availability is not affected. The attack requires local access and user interaction to extract the archive.

Mitigation Recommendations

Do not rely solely on the --one-top-level option to confine extraction of untrusted archives. Instead, extract archives as an unprivileged user into a freshly created empty directory after changing into that directory (using mkdir and cd). Avoid extracting as root from sensitive directories such as /. Follow GNU tar security guidance for handling untrusted archives. Currently, no fixed packages are available, so these mitigations are necessary until a patch is released.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-4f5j-wqjr-hx49
Osv Schema Version
1.4.0
Aliases
["CVE-2026-18508"]
Ecosystems
[]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6a710659bf32cb7a3439375d

Added to database: 08/03/2026, 21:21:29 UTC

Last enriched: 08/03/2026, 21:28:09 UTC

Last updated: 08/04/2026, 03:17:47 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses