Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in GNU tar. The --one-top-level option is intended to confine extraction under a designated directory, but hardlink targets from the archive are not confined the same way and are resolved relative to the extraction working directory (or the directory given with -C). A crafted archive can create hardlinks inside the --one-top-level directory that point to files outside it. If a suitable symbolic link already exists under the extraction working directory, hardlinking to that symlink can bypass tar's usual symlink-based path protections and allow writing outside the intended top-level directory during a single extraction. Users who rely on --one-top-level as a security boundary when extracting untrusted archives may be affected.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:61581 https://access.redhat.com/errata/RHSA-2026:61581
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:61586 https://access.redhat.com/errata/RHSA-2026:61586
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:70390 https://access.redhat.com/errata/RHSA-2026:70390