🔐 CVE Alert

CVE-2026-18477

MEDIUM 4.4

Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape

CVSS Score
4.4
EPSS Score
0.0%
EPSS Percentile
0th

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.

CWE CWE-367
Vendor red hat
Product red hat enterprise linux 10
Published Aug 3, 2026
Last Updated Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat enterprise linux 10

Be the first to know when new medium vulnerabilities affecting red hat red hat enterprise linux 10 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 6
All versions affected
Red Hat / Red Hat Enterprise Linux 7
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Hardened Images
All versions affected
Red Hat / Red Hat Hardened Images
All versions affected
Red Hat / Red Hat Hardened Images
All versions affected
Red Hat / Red Hat Hardened Images
All versions affected
Red Hat / Red Hat Hardened Images
All versions affected
Red Hat / Red Hat Hardened Images
All versions affected
Red Hat / Red Hat Hardened Images
All versions affected
Red Hat / Red Hat Hardened Images
All versions affected
Red Hat / Red Hat Hardened Images
All versions affected
Red Hat / Red Hat Hardened Images
All versions affected
Red Hat / Red Hat Hardened Images
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected

References

NVD ↗ CVE.org ↗ EPSS Data ↗
access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-18477 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2509735

Credits

Red Hat would like to thank Marcin Wyczechowski (AFINE Team) and Michał Majchrowicz (AFINE Team) for reporting this issue.