What is CVE-2026-18508?
A vulnerability in GNU tar allows hardlink targets to escape the designated top-level directory when extracting with `--one-top-level`. This could let a crafted archive create hardlinks outside the intended boundary. Users should update to the latest patched version.
Azərbaycanca: GNU tar-da `--one-top-level` seçimi ilə arxiv çıxarılarkən hardlink hədəflərinin qorunan qovluq xaricinə çıxmasına imkan verən boşluq aşkarlanıb. Bu, xüsusi hazırlanmış arxiv vasitəsilə hücumçuya fayl sisteminə icazəsiz yazma imkanı yaradır. İstifadəçilərə GNU tar-ın ən son yeniləməsini tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What security issue exists in GNU tar when using the `--one-top-level` option?
A specially crafted archive can cause hardlink targets to escape the protected top-level directory, potentially allowing an attacker to write to unauthorized locations on the file system.
How can users protect themselves against the CVE-2026-18508 vulnerability?
Users are advised to update to the latest patched version of GNU tar.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.