CVE-2026-18477
published 2026-08-03CVE-2026-18477: A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a…
PriorityP423medium4.4CVSS 3.1
AVLACHPRLUIRSUCNIHAN
EPSS
0.08%
0.2th percentile
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | tar | — | — |
| gnu | tar | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restor
ghsa_unreviewed·2026-08-03
CVE-2026-18477 [MEDIUM] CWE-367 A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restor
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
Red Hat
tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape
vendor_redhat·2026-07-31·CVSS 4.4
CVE-2026-18477 [MEDIUM] CWE-367 tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape
tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitig
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-18477 tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape [fedora-all]
bugzilla·2026-07-31
CVE-2026-18477 [MEDIUM] CVE-2026-18477 tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape [fedora-all]
CVE-2026-18477 tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modificati
Bugzilla
CVE-2026-18477 tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape
bugzilla·2026-07-31·CVSS 4.4
CVE-2026-18477 [MEDIUM] CVE-2026-18477 tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape
CVE-2026-18477 tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P opti
2026-08-03
Published