Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-18477— Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GNU tar是美国GNU基金会开源的一个文件归档工具。 GNU tar存在竞争条件问题漏洞,该漏洞源于增量dumpdir 'X'重命名处理中的TOCTOU竞争条件问题,可能导致本地攻击者在恢复过程中于预期提取目录之外创建、重命名或覆盖文件,从而导致未授权文件修改或权限提升。

CVSS 4.4 · Medium EPSS 0.08% · P0

Affected Version Matrix 24

VendorProduct Version RangeStatus
Red Hat Red Hat Discovery 2 1788205779< * unaffected
Red Hat Red Hat Enterprise Linux 10 2:1.35-13.el10_2< * unaffected
Red Hat Red Hat Enterprise Linux 6 any unknown
Red Hat Red Hat Enterprise Linux 7 any unknown
Red Hat Red Hat Enterprise Linux 8 2:1.30-13.el8_10< * unaffected
Red Hat Red Hat Enterprise Linux 9 2:1.34-13.el9_8< * unaffected
Red Hat Red Hat Hardened Images 1.35-9.1.hum1< * unaffected
any unaffected
any unaffected
any unaffected
any unaffected
any unaffected
any unaffected
any unaffected
… +3 more rows
Red Hat Red Hat OpenShift Container Platform 4 any affected
any affected
Red Hat Red Hat Update Infrastructure 5 1788880445< * unaffected
1788880464< * unaffected
1788880456< * unaffected
1788765051< * unaffected
1788880581< * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18477

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape
Source: CVE Program / CVE List V5
Vulnerability Description
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Source: CVE Program / CVE List V5
Vulnerability Title
GNU tar 竞争条件问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GNU tar是美国GNU基金会开源的一个文件归档工具。 GNU tar存在竞争条件问题漏洞,该漏洞源于增量dumpdir 'X'重命名处理中的TOCTOU竞争条件问题,可能导致本地攻击者在恢复过程中于预期提取目录之外创建、重命名或覆盖文件,从而导致未授权文件修改或权限提升。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 2:1.35-13.el10_2 ~ * cpe:/o:redhat:enterprise_linux:10.2
Red Hat Red Hat Enterprise Linux 8 2:1.30-13.el8_10 ~ * cpe:/o:redhat:enterprise_linux:8::baseos
Red Hat Red Hat Enterprise Linux 9 2:1.34-13.el9_8 ~ * cpe:/o:redhat:enterprise_linux:9::baseos
Red Hat Red Hat Discovery 2 1788205779 ~ * cpe:/a:redhat:discovery:2::el9
Red Hat Red Hat Hardened Images 1.35-9.1.hum1 ~ * cpe:/a:redhat:hummingbird:1
Red Hat Red Hat Update Infrastructure 5 1788880445 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1788880464 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1788880456 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1788765051 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1788880581 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-18477

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18477

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-18477 (7)

Same Patch Batch · Red Hat · 2026-08-03 · 6 CVEs total

CVE-2026-68742 5.5 MEDIUM Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr
CVE-2026-6695 5.5 MEDIUM Gimp: gimp: remote code execution via crafted paa file
CVE-2026-6694 5.5 MEDIUM Gimp: gimp file-png plugin: denial of service via oversized apng trns chunk
CVE-2026-18651 5.4 MEDIUM 389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-l
CVE-2026-18508 4.4 MEDIUM Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling ar

IV. Related Vulnerabilities

V. Comments for CVE-2026-18477

No comments yet


Leave a comment