CVE-2026-18508
Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
Record summary
CVE-2026-18508 has a selected CVSS score of 4.4 (medium).
Description
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2026 · Source: CVE List
Affected products and versions
Showing 12 of 17| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | Version data not supplied | |
Default status: unknown | CVE List | Version data not supplied | |
Default status: unknown | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |