Impact
A flaw in GNU tar allows hardlink targets to escape the intended top‑level directory when the --one-top-level option is used. A crafted archive can create hardlinks that resolve relative to the extraction working directory. If a symbolic link already exists in that working directory, the extraction can write files outside the confined directory. This vulnerability enables an attacker to overwrite arbitrary files, potentially compromising system integrity and escalating privileges if executed with root.
Affected Systems
This flaw affects Red Hat Enterprise Linux releases 6 via 10, Red Hat Hardened Images, and Red Hat OpenShift Container Platform 4. No specific sub‑versions are identified in the advisory, so any systems running GNU tar before the fix are potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.4 denotes moderate severity. The exploit would require an attacker to execute the tar extraction as a privileged user and craft a target archive with hardlinks. While the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the lack of early discovery suggests a lower likelihood of widespread exploitation. Nevertheless, if the conditions for extraction are met, an attacker could overwrite critical files and potentially gain elevated privileges.
OpenCVE Enrichment