4.4
CVE-2026-18477
- EPSS 0.1%
- Veröffentlicht 03.08.2026 15:34:36
- Zuletzt bearbeitet 22.09.2026 22:17:11
- Erkennungen
Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Openshift Container Platform Version 4.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Version 10.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.012 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
|
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
https://access.redhat.com/security/cve/CVE-2026-18477
https://bugzilla.redhat.com/show_bug.cgi?id=2509735
https://access.redhat.com/errata/RHSA-2026:49361
https://access.redhat.com/errata/RHSA-2026:61581
https://access.redhat.com/errata/RHSA-2026:61783
https://access.redhat.com/errata/RHSA-2026:61586
https://access.redhat.com/errata/RHSA-2026:66018
https://access.redhat.com/errata/RHSA-2026:70390