Bug 2493710 (CVE-2026-29509)
| Summary: | CVE-2026-29509 patool: Patool: Arbitrary file write via path traversal in archive extraction | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Patool. A remote attacker could exploit a path traversal vulnerability in the `safe_extract()` function by providing a specially crafted archive. This vulnerability arises because a helper function uses an insecure comparison method, allowing malicious paths to bypass security checks. Successful exploitation could enable the attacker to write arbitrary files to unintended locations on the system, potentially leading to information disclosure or system compromise.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-06-26 21:02:13 UTC
|