Impact
A flaw exists in the sos clean utility of the sos package; a local attacker can craft a tar archive with symlinks or hardlinks that point outside the extraction path, and sos clean does not validate these targets, enabling the attacker to create or overwrite any file on the system under the process's privilege level. Because sos clean often runs as root, the attacker can modify critical system files, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux releases 6 through 10, as any system running the sos package on these platforms is susceptible until the distributed package is updated by the vendor.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. EPSS information is not available and the vulnerability is not listed in CISA KEV, meaning no publicly documented exploits exist yet. Exploitation requires a local attacker who can trigger sos clean to process a specially crafted archive, and it hinges on user interaction to run the extraction routine. If achieved, the attacker can write arbitrary files with root privileges, enabling privilege escalation and denial of service.
OpenCVE Enrichment