Description
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality.

This issue affects pardus-image-writer: before 0.9.0.
Published: 2026-08-04
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an external control of file name or path supplied to pardus‑image‑writer. The missing validation allows an attacker to specify arbitrary paths, which the application uses to write directly to any block device. This can erase or corrupt critical data and effectively remove important client functionality. The weakness maps to CWE‑73, and while it primarily threatens the integrity and availability of underlying storage, confidentiality is not directly affected.

Affected Systems

The flaw affects TÜBİTAK BİLGEM Software Technologies Research Institute's pardus‑image‑writer prior to version 0.9.0. Users running these earlier releases are vulnerable to the unchecked write operation.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability falls into the medium‑to‑high severity range. The EPSS score is < 1 % and the vulnerability is not listed in CISA's KEV catalog, indicating limited known exploitation. The likely attack path requires an attacker who can provide or influence the file name or path argument—either through user input or a compromised local account—so exploitation is inferred to be local or via command‑line interaction. Because the attacker can overwrite arbitrary block devices, immediate remedial action is recommended to mitigate potential data loss.

Generated by OpenCVE AI on August 10, 2026 at 12:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update pardus‑image‑writer to version 0.9.0 or newer.
  • Restrict the application’s file system permissions so that it cannot write to arbitrary block devices, enforcing least privilege.
  • Apply a code patch that validates and sanitizes all pathname inputs before performing device writes.

Generated by OpenCVE AI on August 10, 2026 at 12:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: before 1.0.4. External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: before 0.9.0.

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Tubitak Bilgem Software Technologies Research Institute
Tubitak Bilgem Software Technologies Research Institute pardus-image-writer
Vendors & Products Tubitak Bilgem Software Technologies Research Institute
Tubitak Bilgem Software Technologies Research Institute pardus-image-writer

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: before 1.0.4.
Title Arbitrary Block Device Write via Missing Validation in TÜBİTAK BİLGEM's pardus-image-writer
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Tubitak Bilgem Software Technologies Research Institute Pardus-image-writer
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-10T11:33:53.118Z

Reserved: 2026-08-04T12:12:44.857Z

Link: CVE-2026-18806

cve-icon Vulnrichment

Updated: 2026-08-04T15:37:43.214Z

cve-icon NVD

Status : Received

Published: 2026-08-04T13:17:36.540

Modified: 2026-08-10T12:17:14.303

Link: CVE-2026-18806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T13:00:04Z

Weaknesses
  • CWE-73

    External Control of File Name or Path