CVE-2026-18477

NameCVE-2026-18477
DescriptionA TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1143836

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tar (PTS)bullseye1.34+dfsg-1+deb11u1vulnerable
bookworm1.34+dfsg-1.2+deb12u1vulnerable
trixie1.35+dfsg-3.1vulnerable
forky, sid1.35+dfsg-5vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tarsource(unstable)(unfixed)1143836

Notes

[trixie] - tar <no-dsa> (Minor issue)
https://bugzilla.redhat.com/show_bug.cgi?id=2509735

Search for package or bug name: Reporting problems