CyberICT

CVE-2026-18508

Microsoft · Published August 7, 2026

CVSS v3.1

MEDIUM
Patch availableGet patch

Description

Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite. Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite

Affected Products

  • azl3 tar 1.35-2 on Azure Linux 3.0

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N