Record summary

CVE-2026-18477 has a selected CVSS score of 4.4 (medium).

Description

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2026 · Source: CVE List

Affected products and versions

Showing 12 of 17
ProductSourceVersion rangeStatus

Red Hat Enterprise Linux 10

Browse Red Hat / Red Hat Enterprise Linux 10tar

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 6

Browse Red Hat / Red Hat Enterprise Linux 6tar

Default status: unknown

CVE ListVersion data not supplied

Red Hat Enterprise Linux 7

Browse Red Hat / Red Hat Enterprise Linux 7tar

Default status: unknown

CVE ListVersion data not supplied

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8tar

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 9

Browse Red Hat / Red Hat Enterprise Linux 9tar

Default status: affected

CVE ListVersion data not supplied

Red Hat Hardened Images

Browse Red Hat / Red Hat Hardened Imagesaardvark-dns

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Hardened Images

Browse Red Hat / Red Hat Hardened Imageschunkah

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Hardened Images

Browse Red Hat / Red Hat Hardened Imagesgrafana12.4

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Hardened Images

Browse Red Hat / Red Hat Hardened Imagesgrafana13.1

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Hardened Images

Browse Red Hat / Red Hat Hardened Imagesnetavark

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Hardened Images

Browse Red Hat / Red Hat Hardened Imagesnodejs26

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Hardened Images

Browse Red Hat / Red Hat Hardened Imagespython-cryptography

Default status: unaffected

CVE ListVersion data not supplied

References

4