{"id":"AZL-105962","summary":"CVE-2026-105712 affecting package gnupg2 2.4.9-3","details":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.","modified":"2026-10-07T05:34:51Z","published":"2026-10-05T19:17:19Z","upstream":["CVE-2026-105712"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712"}],"affected":[{"package":{"name":"gnupg2","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/gnupg2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.4.9-3"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105962.json"}}],"schema_version":"1.9.0"}