CVE-2026-108119
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal in BusyBox tar Applet

Vulnerability report for CVE-2026-108119, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: redhat-SADP

Description

A flaw was found in busybox. The tar applet's deferred link-creation handling for symlink and hardlink entries with unsafe-looking targets does not validate that the resolved destination remains inside the extraction directory once the deferred link is created. An attacker can craft a tar archive using a symlink target of exactly '..' combined with a deferred hardlink to create a new file outside the extraction directory, or reuse an extraction directory across two archives to replace an existing file outside it. If the archive is extracted with elevated privileges, this flaw can lead to privilege escalation or arbitrary code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
busybox busybox *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the tar applet of busybox. It involves improper handling of symlink and hardlink entries in tar archives. When extracting archives with elevated privileges, an attacker could create files outside the intended directory by exploiting deferred link creation, potentially leading to privilege escalation or arbitrary code execution.

Detection Guidance

This vulnerability is specific to the busybox tar applet and cannot be directly detected via network scanning. To check if your system uses a vulnerable version of busybox, run: busybox | grep tar. If the tar applet is present, verify the version with busybox | head -n 1. Compare the version against the patched release.

Impact Analysis

If you extract a malicious tar archive with elevated privileges, this flaw could allow an attacker to overwrite critical system files, execute arbitrary code, or gain elevated system access. Users with standard privileges may face unauthorized file modifications or system compromise.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality principles or HIPAA's security requirements. Compliance may be compromised if sensitive data is exposed or altered due to exploitation.

Mitigation Strategies

Update busybox to the latest patched version immediately. Avoid extracting untrusted tar archives with elevated privileges. If extraction is necessary, use a sandboxed environment or a non-vulnerable tool like GNU tar. Monitor for unusual file creation outside expected directories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108119. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart