Libarchive through 3.6.2 can cause directories to have world-writable permissions.
Libarchive versions through 3.6.2 contain a race condition in the umask() call that can cause directories to be created with world-writable permissions (0777) without the sticky bit. This occurs because the umask change affects the entire process briefly, and concurrent threads can cause the umask to remain at 0 permanently. As a result, low-privileged local users may gain the ability to delete or rename files within these directories.
AI Analysis
Technical Summary
Libarchive versions up to and including 3.6.2 have a vulnerability where a race condition in the umask() call inside archive_write_disk_posix.c can cause the process umask to be permanently set to 0. This leads to implicit directory creation with overly permissive 0777 permissions lacking the sticky bit. Consequently, any low-privileged local user can delete or rename files inside these directories due to the world-writable permissions.
Potential Impact
The vulnerability allows local low-privileged users to manipulate files in directories created by libarchive with world-writable permissions. This can lead to unauthorized file deletion or renaming, potentially impacting system integrity and availability. There is no indication of confidentiality or direct code execution impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a patch is confirmed, avoid running libarchive in multi-threaded environments where this race condition could be exploited, or restrict local user access to systems using vulnerable versions. Monitor vendor channels for official fixes.
Libarchive through 3.6.2 can cause directories to have world-writable permissions.
Description
Libarchive versions through 3.6.2 contain a race condition in the umask() call that can cause directories to be created with world-writable permissions (0777) without the sticky bit. This occurs because the umask change affects the entire process briefly, and concurrent threads can cause the umask to remain at 0 permanently. As a result, low-privileged local users may gain the ability to delete or rename files within these directories.
CVSS v3.1
Score 5.3medium
Affected software
pkg:deb/ubuntu/[email protected]+esm5?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/[email protected]?arch=source&distro=jammyRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Libarchive versions up to and including 3.6.2 have a vulnerability where a race condition in the umask() call inside archive_write_disk_posix.c can cause the process umask to be permanently set to 0. This leads to implicit directory creation with overly permissive 0777 permissions lacking the sticky bit. Consequently, any low-privileged local user can delete or rename files inside these directories due to the world-writable permissions.
Potential Impact
The vulnerability allows local low-privileged users to manipulate files in directories created by libarchive with world-writable permissions. This can lead to unauthorized file deletion or renaming, potentially impacting system integrity and availability. There is no indication of confidentiality or direct code execution impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a patch is confirmed, avoid running libarchive in multi-threaded environments where this race condition could be exploited, or restrict local user access to systems using vulnerable versions. Monitor vendor channels for official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2023-30571
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a600ab59c2644c7f8fe2131
Added to database: 07/22/2026, 00:11:33 UTC
Last enriched: 07/22/2026, 00:48:49 UTC
Last updated: 09/10/2026, 19:36:47 UTC
Views: 26
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.