{"id":"AZL-103254","summary":"CVE-2026-88922 affecting package packer 1.9.5-20","details":"The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bits. Where extraction is performed by a privileged user, this may allow a local actor to obtain the privileges of the extracting process. This vulnerability (CVE-2026-88922) is fixed in go-getter 1.8.9 and 2.2.4.","modified":"2026-09-22T05:34:53Z","published":"2026-09-15T20:19:19Z","upstream":["CVE-2026-88922"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88922"}],"affected":[{"package":{"name":"packer","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/packer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.9.5-20"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103254.json"}}],"schema_version":"1.9.0"}