CVE-2026-108119: Busybox: busybox: tar extraction-root escape via deferred symlink/hardlink creation bypasses cve-2026-26158 fix

Published Oct 9, 2026
·
Updated

A flaw was found in busybox. The tar applet defers creation of symlink and hardlink entries whose targets look unsafe (absolute paths, hardlinks, or targets containing '..') until after all archive members have been processed, in order to avoid a same-archive time-of-check-to-time-of-use issue. However, when those deferred links are finally created, the code performs the underlying symlink() or link() system call directly, without re-validating that the resolved destination parent remains inside the extraction directory. By chaining an immediately-created symlink with a deferred symlink whose target is exactly '..' (a value not caught by the separate prefix-based sanitizer applied to member names, which only strips leading '../' and embedded '/../' sequences), an attacker can make a path that appears to be inside the extraction directory resolve outside it once the deferred link is created. Combined with a deferred hardlink in the same archive, this creates a new file outside the extraction directory; reusing the same destination directory across two archives allows an existing external file to be deleted and replaced with attacker-controlled content, including attacker-controlled ownership and permissions for privileged extraction, since the second archive's replacement member is an ordinary file entry (not a hardlink) and is subject to busybox tar's normal chown()/chmod() restoration from the archive header. The one-archive hardlink primitive requires the internal source file and the external target to reside on the same filesystem; the two-archive primitive requires the extraction directory to be reused across two extraction invocations.

Other sources

A flaw was found in busybox. The tar applet's deferred link-creation handling for symlink and hardlink entries with unsafe-looking targets does not validate that the resolved destination remains inside the extraction directory once the deferred link is created. An attacker can craft a tar archive using a symlink target of exactly '..' combined with a deferred hardlink to create a new file outside the extraction directory, or reuse an extraction directory across two archives to replace an existing file outside it. If the archive is extracted with elevated privileges, this flaw can lead to privilege escalation or arbitrary code execution.

— MITRE

Affected Software

1 affected component
Busybox Busybox

Event History

Oct 9, 2026
Data Sourced
via Red Hat·02:14 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Systems using the BusyBox tar applet to extract attacker-controlled archives are exposed. Exploitation requires a user to extract the crafted archive, consistent with the user-interaction requirement in the severity vector.

2

What must a crafted archive contain to exploit the flaw?

The archive chains an immediately created symlink with a deferred symlink whose target is exactly '..', then uses a deferred hardlink. This causes a path that appears to remain under the extraction directory to resolve outside it when deferred links are created.

3

When can an attacker replace an existing file outside the extraction directory?

Creating a new external file can occur with the crafted links and hardlink in one archive. Deleting and replacing an existing external file with attacker-controlled content requires reusing the same destination directory across two archives.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203