PT-2026-43162 · Bingos · Archive Tar

Published

2026-05-26

·

Updated

2026-05-26

·

CVE-2026-42496

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.
make special file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.
A subsequent open through the extracted name reads or writes the attacker chosen path.

Link Following

Weakness Enumeration

Related Identifiers

CVE-2026-42496

Affected Products

Archive Tar