Bug 2518147 (CVE-2026-17106)
| Summary: | CVE-2026-17106 github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | aazores, akhatavk, amctagga, aoconnor, aos-team-art-private, aruklets, asdas, bniver, cahl, cdrage, cmah, crizzo, dfreiber, dkeler, doconnor, dpaolell, drow, dschmidt, eaguilar, ebaron, eborisov, eglynn, flucifre, gmeno, gparvin, groman, gtanzill, jbalunas, jburrell, jbuscemi, jcantril, jdelft, jjoyce, jlanda, jmatsuok, jpretori, jschluet, jtolenti, jupierce, kaycoth, kshier, lball, lchilton, lgarciaa, lhh, ljawale, mbenjamin, mbiarnes, mburns, mgarciac, mhackett, msilmser, ngough, pjindal, ppalepu, ppostler, prdhamdh, rekumar, rhaigner, rhel-process-autobot, rojacob, rushinde, sdawley, sfeifer, sghai, sidsharm, simaishi, sostapov, stcannon, suppawar, teagle, thason, tsze, vereddy, veshanka, vkumar, vlaad, vvoronko, watson-tool-maintainers, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in moby/go-archive. The tar extraction routines in the component do not properly restrict filesystem operations to the intended destination directory. An attacker who controls the contents of an archive can exploit this by including symbolic links, allowing them to create or overwrite files at arbitrary locations on the system where the archive is being extracted. This could lead to unauthorized modification of system files or potentially arbitrary code execution.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2526988, 2526989, 2526990 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-08-18 18:51:29 UTC
|