Impact
The vulnerability resides in the Builder::append_dir_all() function of tar-rs versions 0.4.11 through 0.4.46. It permits an attacker to plant symlinks inside an untrusted directory and cause a privileged process to archive files outside the intended source root, treating those files as regular archive contents. This flaw can result in reading sensitive data that the architecture was not designed to expose.
Affected Systems
The affected vendor is composefs, with the tar-rs library. Versions identified as vulnerable span 0.4.11 up to and including 0.4.46.
Risk and Exploitability
The CVSS score of 7.1 places the vulnerability in the high severity range, though the EPSS score is not available, leaving the likelihood of exploitation uncertain. The flaw is not currently listed in CISA KEV. The attack vector requires an attacker to supply a directory that a privileged archiving process will process; thus the approach is most relevant in a local or privileged context where the attacker can influence the input to the archive function. Once exploited, the attacker can read arbitrary files from the file system as the privileged process owner.
OpenCVE Enrichment