CVE-2026-18806: Arbitrary Block Device Write via Missing Validation in TÜBİTAK BİLGEM's pardus-image-writer
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality.
This issue affects pardus-image-writer: before 1.0.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pardus-image-writerto a version that resolves this vulnerability.Fixed in 1.0.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18806?
CVE-2026-18806 has a high severity rating of 7.1.
What are the affected versions for CVE-2026-18806?
CVE-2026-18806 affects versions of TÜBİTAK BİLGEM pardus-image-writer prior to 1.0.4.
How does CVE-2026-18806 affect users?
CVE-2026-18806 allows for the arbitrary write of block devices, which can remove important client functionality.
How do I fix CVE-2026-18806?
To fix CVE-2026-18806, upgrade the TÜBİTAK BİLGEM pardus-image-writer to version 1.0.4 or later.
What type of vulnerability is CVE-2026-18806?
CVE-2026-18806 is an external control of file name or path vulnerability.