Impact
The container storage library accepts a maliciously crafted tar archive containing a whiteout header such as victim/.wh. When the archive is processed by UnpackLayer, ApplyLayer, or ApplyUncompressedLayer, the named extraction directory can be replaced with an arbitrary file. The primary impact is that an attacker could overwrite any file within the extraction target, potentially allowing deployment of malicious code, tampering with configuration files, or altering privileged data if the container process runs with elevated privileges.
Affected Systems
Affected products include Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 8, 9 and 10, Red Hat OpenShift Container Platform 4, OpenShift Dev Spaces, Quay 3, Container Native Virtualization 4, and Red Hat Hardened Images; all rely on the containers/storage component. No specific affected-version information is available.
Risk and Exploitability
The CVSS score of 4.4 indicates low severity and the EPSS score of less than 1% denotes a very small likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to supply a crafted tar archive during a container image build or deployment, making the attack scenario limited to environments that routinely extract untrusted tar archives.
OpenCVE Enrichment