Description
gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.
Published: 2026-10-05
Score: 3.6 Low
EPSS: n/a
KEV: No
Impact: File Overwrite via Symlink
Action: Update Software
AI Analysis

Impact

gpgtar, the archiving component of GnuPG, can follow symbolic links when extracting an archive with the --directory flag. A malicious archive that includes a symlink pointing outside the selected extraction directory can cause gpgtar to create or overwrite files that are outside the intended boundary. This flaw allows an attacker to write arbitrary data to locations where the extracting user has write permission, potentially compromising configuration files or other sensitive data, but the impact is limited to the scope of the user’s filesystem rights.

Affected Systems

The flaw exists in all GnuPG versions prior to 2.5.19. Every build distributed under the GnuPG project is affected until the public release that removes the vulnerable behaviour, version 2.5.19 and later, contains the fix.

Risk and Exploitability

The CVSS score of 3.6 indicates low‑to‑moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. Exploitation requires an attacker to supply a crafted archive to a user who runs gpgtar with the --directory switch inside a directory that already contains a pre‑existing symlink. The overwrite is constrained by the extracting user’s filesystem permissions, so the attacker can only affect files in locations where that user can write.

Generated by OpenCVE AI on October 5, 2026 at 21:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GnuPG to version 2.5.19 or later where the gpgtar symlink follow behaviour is corrected.
  • Avoid giving gpgtar the --directory option with archives from untrusted sources, or run the extraction in a fresh, empty directory that contains no pre‑existing symlinks.
  • Restrict the filesystem permissions of users who run gpgtar so that even if a symlink is followed, they cannot write to critical system files.

Generated by OpenCVE AI on October 5, 2026 at 21:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.
First Time appeared Gnupg
Gnupg gnupg
Weaknesses CWE-61
CPEs cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:*
Vendors & Products Gnupg
Gnupg gnupg
References
Metrics cvssV3_1

{'score': 3.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-05T19:09:30.980Z

Reserved: 2026-10-05T18:53:09.023Z

Link: CVE-2026-105712

cve-icon Vulnrichment

Updated: 2026-10-05T19:09:26.691Z

cve-icon NVD

Status : Received

Published: 2026-10-05T19:17:19.527

Modified: 2026-10-05T20:17:20.460

Link: CVE-2026-105712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:15:15Z

Weaknesses
  • CWE-61

    UNIX Symbolic Link (Symlink) Following