CVE-2026-70622
Public on 2026-08-10
Modified on 2026-08-13
Description
tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-controlled directory. When a privileged process archives an untrusted directory, the function follows symlinks without verifying that resolved targets remain within the source root, causing out-of-bounds files to be included in the archive as regular files and disclosed to the attacker.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | aws-nitro-enclaves-cli | Pending Fix | ||
| Amazon Linux 2023 | aws-nitro-enclaves-cli | Pending Fix | ||
| Amazon Linux 2023 | clamav1.5 | Pending Fix | ||
| Amazon Linux 2 - Core | rust | Pending Fix | ||
| Amazon Linux 2023 | rust | Pending Fix | ||
| Amazon Linux 2023 | rust-below | Pending Fix | ||
| Amazon Linux 2023 | rust-cargo-c | Pending Fix | ||
| Amazon Linux 2 - Core | tar | Not Affected | ||
| Amazon Linux 2023 | tar | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 5.0 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |