CVE-2026-18508
published 2026-08-03CVE-2026-18508: A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level…
PriorityP420medium4.4CVSS 3.1
AVLACLPRNUIRSUCLILAN
EPSS
0.14%
3.7th percentile
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | tar | — | — |
| gnu | tar | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
vendor_redhat·2026-07-31·CVSS 4.4
CVE-2026-18508 [MEDIUM] CWE-59 tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
Statement: Red Hat Enterprise Linux is affected. This issue only applies when the --one-top-level option is used to extract an untrusted archive. Default tar extraction without --one-top-level is not impacted by this specific boundary failu
GHSA
A flaw was found in GNU tar.
ghsa_unreviewed·2026-08-03
CVE-2026-18508 [MEDIUM] CWE-59 A flaw was found in GNU tar.
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-18508 tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite [fedora-all]
bugzilla·2026-07-31
CVE-2026-18508 [MEDIUM] CVE-2026-18508 tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite [fedora-all]
CVE-2026-18508 tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw was found in GNU tar. The --one-top-level option is intended to confine extraction under a designated directory, but hardlink targets from the archive are not confined the same way and are resolved relative to the extraction working directory (or the directory given with -C). A crafted archive can create hardlinks inside the --one-top-level directory that point to files outside it. If a suitable symbolic link already exist
Bugzilla
CVE-2026-18508 tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
bugzilla·2026-07-31·CVSS 4.4
CVE-2026-18508 [MEDIUM] CVE-2026-18508 tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
CVE-2026-18508 tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
A flaw was found in GNU tar. The --one-top-level option is intended to confine extraction under a designated directory, but hardlink targets from the archive are not confined the same way and are resolved relative to the extraction working directory (or the directory given with -C). A crafted archive can create hardlinks inside the --one-top-level directory that point to files outside it. If a suitable symbolic link already exists under the extraction working directory, hardlinking to that symlink can bypass tar's usual symlink-based path protections and allow writing outside the intended top-level directory during a single extraction. Users who rely on --one-top
2026-08-03
Published