CVE-2026-79655

NameCVE-2026-79655
DescriptionA flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issue during tar extraction, where symlink and hardlink targets are not properly validated. This enables the attacker to write files to arbitrary locations on the system with the privileges of the sos clean process, which often runs as root.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
sos (PTS)trixie4.9.1-1vulnerable
forky, sid4.11.2-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
sossource(unstable)(unfixed)
sospreortsource(unstable)(unfixed)

Notes

https://github.com/sosreport/sos/issues/4460
https://github.com/sosreport/sos/pull/4461

Search for package or bug name: Reporting problems