Fedora Account System
Red Hat Associate
Red Hat Customer
Upstream issue: https://github.com/sosreport/sos/issues/4460 Proposed Fix: https://github.com/sosreport/sos/pull/4461 Component: sos (sos/cleaner/archives/_init_.py — extract_archive()) CWE: CWE-22 and CWE-59 Suggested CVSS 3.1: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (7.8) Summary: sos clean extracts a caller-supplied tarball with tarfile.fully_trusted_filter. A dest-containment check exists but only inspects member.name. It does not inspect symlink or hardlink targets. extractall() can therefore write files outside the extract directory as the process UID. Description: A path traversal vulnerability was found in sos clean in the sos package. The extract_archive() function uses Python's tarfile module with fully_trusted_filter and validates only archive member names against the extraction directory. Symlink and hardlink targets are not validated. A crafted tar archive can therefore contain an out-of-tree symlink followed by a regular file whose apparent path remains within the extraction directory. During extraction, tarfile.extractall() follows the symlink and writes the file to an attacker-controlled location outside the extraction directory. This can result in arbitrary file creation or overwrite with the privileges of the sos clean process, which is commonly run as root. Reporter / Credit: Sandipan Roy (Red Hat)