CVE-2026-18477: Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18477?
CVE-2026-18477 has a medium severity rating of 4.4.
How do I fix CVE-2026-18477?
To address CVE-2026-18477, update GNU tar to the latest version that contains the security patch.
What does CVE-2026-18477 allow an attacker to do?
CVE-2026-18477 allows a local attacker to influence the restore process by exploiting a TOCTOU vulnerability.
Who is affected by CVE-2026-18477?
Users of GNU tar with write access to the backup directory are affected by CVE-2026-18477.
When was CVE-2026-18477 published?
CVE-2026-18477 was published on August 3, 2026.