Fedora Account System
Red Hat Associate
Red Hat Customer
tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory. This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:54268 https://access.redhat.com/errata/RHSA-2026:54268
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:56219 https://access.redhat.com/errata/RHSA-2026:56219
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:58902 https://access.redhat.com/errata/RHSA-2026:58902
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:58901 https://access.redhat.com/errata/RHSA-2026:58901
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:58928 https://access.redhat.com/errata/RHSA-2026:58928
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:58971 https://access.redhat.com/errata/RHSA-2026:58971
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:59009 https://access.redhat.com/errata/RHSA-2026:59009
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:62809 https://access.redhat.com/errata/RHSA-2026:62809
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:63024 https://access.redhat.com/errata/RHSA-2026:63024