Bug 2430538 (CVE-2026-23745)
| Summary: | CVE-2026-23745 node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | aazores, abarbaro, abrianik, abuckta, akostadi, alcohan, alizardo, amasferr, anjoseph, anpicker, anthomas, anujha, aruklets, aschwart, asoldano, aszczucz, ataylor, bbaranow, bbrownin, bdettelb, bmaxwell, boliveir, brian.stansberry, bstansbe, carogers, caswilli, cmah, darran.lofthouse, dbosanac, dbruscin, dfreiber, dhanak, dkuc, dlofthou, dmayorov, doconnor, dosoudil, drichtar, drosa, drow, dschmidt, dsimansk, dymurray, eaguilar, ebaron, eborisov, ehelms, ehugonne, erezende, ggainey, ggrzybek, gmalinko, gparvin, haoli, hasun, hkataria, ibek, ibolton, istudens, ivassile, iweiss, jajackso, janstey, jbalunas, jburrell, jcammara, jcantril, jchui, jfula, jhe, jkoehler, jlanda, jlledo, jmatthew, jmitchel, jmontleo, jneedle, jolong, jowilson, jpasqual, jprabhak, jraez, jreimann, jrokos, juwatts, kaycoth, kegrant, kingland, koliveir, kshier, ktsao, kvanderr, kverlaen, lball, lchilton, lphiri, mabashia, manissin, mattdavi, matzew, mdessi, mhulan, mnovotny, mosmerov, mposolda, mrizzi, mstipich, msvehla, nboldt, ngough, nmoumoul, nwallace, nyancey, oaljalju, ometelka, orabin, osousa, owatkins, pahickey, pantinor, parichar, pberan, pbraun, pcattana, pcreech, pdelbell, pesilva, pgaikwad, pjindal, pmackay, psrna, ptisnovs, rchan, rekumar, rexwhite, rhaigner, rhel-process-autobot, rjohnson, rmartinc, rojacob, rstancel, rstepani, sausingh, sdawley, sfeifer, shvarugh, simaishi, slucidi, smaestri, smallamp, smcdonal, sseago, ssilvert, stcannon, sthirugn, sthorger, syedriko, tasato, teagle, tfister, thavo, thjenkin, tmalecek, tom.jenkinson, tsedmik, vdosoudi, veshanka, vkumar, vmuzikar, vvoronko, watson-tool-maintainers, wtam, xdharmai, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the node-tar library. This vulnerability allows an attacker to craft malicious archives that, when extracted, can bypass intended security restrictions. This leads to arbitrary file overwrite and symlink poisoning, potentially allowing unauthorized modification of files on the system.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2431086, 2431108, 2431109, 2431113, 2431115, 2431116, 2431088, 2431090, 2431092, 2431094, 2431095, 2431096, 2431097, 2431098, 2431099, 2431100, 2431101, 2431102, 2431103, 2431104, 2431105, 2431106, 2431107, 2431110, 2431111, 2431112, 2431114, 2431117 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-01-16 23:01:50 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:18480 https://access.redhat.com/errata/RHSA-2026:18480 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:18868 https://access.redhat.com/errata/RHSA-2026:18868 |