Bug 2509735 (CVE-2026-18477) - CVE-2026-18477 tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape
Summary: CVE-2026-18477 tar: tar: TOCTOU in incremental dumpdir 'X' rename handling al...
Keywords:
Status: NEW
Alias: CVE-2026-18477
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2509846
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-31 10:57 UTC by OSIDB Bzimport
Modified: 2026-08-04 05:21 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-31 10:57:51 UTC
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.


Note You need to log in before you can comment on or make changes to this bug.