CVE-2026-18477
Beschrijving NL
Een TOCTOU-kwetsbaarheid (Time-of-Check Time-of-Use) in GNU tar's incrementele dumpdir 'X' hernoemt de verwerking, waardoor een lokale aanvaller met schrijftoegang tot een map waarvan een back-up wordt gemaakt, het herstelproces kan beïnvloeden als de aanvaller toegang heeft tot het systeem waar het herstel wordt uitgevoerd. Tijdens het herstel kunnen bestanden of mappen worden gemaakt, hernoemd of overschreven buiten de beoogde uitpakmap. Dit kan leiden tot ongeoorloofde bestandswijziging of, in sommige gevallen, escalatie van privileges. Exploitatie vereist niet dat de aanvaller het archief wijzigt of bewerkt, en standaard back-up- en herstelworkflows - inclusief uitpakken in een nieuw aangemaakte map zonder de optie -P te gebruiken - verminderen het probleem niet.
Origineel (Engels) tonen
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.