{"id":"AZL-94599","summary":"CVE-2026-18508 affecting package tar 1.35-2","details":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.","modified":"2026-08-30T05:26:50Z","published":"2026-08-03T16:16:28Z","upstream":["CVE-2026-18508"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18508"}],"affected":[{"package":{"name":"tar","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/tar"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.35-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94599.json"}}],"schema_version":"1.9.0"}