SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2026-18477

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system…

MEDIUM 4.4EPSS 0.08%

Does this matter?

Lower severity and a low EPSS score (0.08%). Track it; it rarely justifies an emergency change on its own.

Description

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.

CVSS 3.1
4.4 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
EPSS
0.08% probability · 0th percentile
CISA KEV
Not listed
Weakness
CWE-367
Affected
gnu/tar · redhat/openshift container platform · redhat/enterprise linux
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.