Fedora Account System
Red Hat Associate
Red Hat Customer
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:30852 https://access.redhat.com/errata/RHSA-2026:30852
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:30851 https://access.redhat.com/errata/RHSA-2026:30851
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:30856 https://access.redhat.com/errata/RHSA-2026:30856
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:30857 https://access.redhat.com/errata/RHSA-2026:30857