CVE-2026-18477 Details
Description
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
A TOCTOU (Time-of-Check Time-of-Use) vulnerability has been identified in GNU Tar's handling of incremental backups. This issue allows a local attacker with write access to a directory being backed up to disrupt the restoration process. If the attacker can access the system where the restoration is taking place, they may influence the extraction by creating, renaming, or overwriting files and directories outside the designated extraction area. Such actions could result in unauthorized modifications of files or, in certain situations, lead to privilege escalation. Notably, exploitation does not require the attacker to alter the backup archive itself, and conventional backup and restore procedures—such as extracting into a newly created directory without the -P option—do not address this vulnerability.
Users are advised to avoid restoring incremental backups on systems where untrusted users have shell access, especially if those users could have modified the backed-up data. When restoring backups that include user-controlled content, it is recommended to do so only on systems that are not accessible to those users.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gnu tar | 1.35 |
CPE
Remediation
| |
| redhat openshift container platform | 4.0 |
CPE
Remediation
| |
| redhat enterprise linux | 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | CVE Modified | [email protected] |
| Sep 10, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 21, 2026 | CVE Modified | [email protected] |
| Aug 13, 2026 | Initial Analysis | [email protected] |
| Aug 5, 2026 | CVE Modified | [email protected] |
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | [email protected] |