What is CVE-2026-18477?
CVE-2026-18477 is a TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling. It allows a local attacker with write access to the directory being backed up to influence the restore process if they also have access to the system where the restore is performed. Affected users should update GNU tar to the latest version and avoid performing restores in untrusted environments.
Azərbaycanca: CVE-2026-18477 GNU tar alətində dumpdir 'X' əmrinin artımlı ad dəyişdirmə (rename) əməliyyatında TOCTOU (Time-of-Check Time-of-Use) zəifliyidir. Bu, ehtiyat nüsxəsi alınan qovluğa yazma icazəsi olan yerli hücumçunun, bərpa əməliyyatı aparılan sistemə girişi varsa, bərpa prosesini manipulyasiya etməsinə imkan verir. Təsirə məruz qalan istifadəçilər GNU tar-ı ən son versiyaya yeniləməli və etibarsız mühitlərdə bərpa əməliyyatlarından qaçınmalıdır.
Related CVEs
link basis: shared vendor: GNU
FAQ2
What privileges does an attacker need to exploit CVE-2026-18477?
The attacker must have access to the system where the restore is performed and also have write access to the directory being backed up.
How can users protect themselves against the CVE-2026-18477 TOCTOU vulnerability?
Users should update GNU tar to the latest version and avoid performing restores in untrusted environments.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.