CVE-2026-105712: Low severity gnupg gpgtar vulnerability
gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.
Affected Software
Event History
Frequently Asked Questions
Which extraction workflows are exposed?
The issue affects gpgtar before 2.5.19 when an untrusted archive is extracted with --directory (-C) into an existing directory that contains a pre-existing symlink. Extracting into a fresh, empty directory does not have this risk.
What does an attacker need to exploit this?
An attacker needs to provide a crafted archive and have a user extract it with gpgtar using --directory (-C) into a directory containing a suitable existing symlink. The attacker does not need privileges, but exploitation requires user interaction.
What can be overwritten?
gpgtar may follow the pre-existing symlink and create or overwrite a file outside the chosen extraction directory. Any resulting write is limited to locations writable by the user performing the extraction.
What is a practical mitigation before upgrading?
Do not extract untrusted archives with --directory (-C) into existing directories that may contain symlinks. Use a newly created, empty extraction directory instead.