CVE-2026-24846: malcontent's archive extraction could write outside extraction directory
malcontent could be made to create symlinks outside the intended extraction directory when scanning a specially crafted tar or deb archive. The handleSymlink function received arguments in the wrong order, causing the symlink target to be used as the symlink location. Additionally, symlink targets were not validated to ensure they resolved within the extraction directory.
Fixes: - Swap handleSymlink arguments; validate symlink location - Validate symlink targets resolve within extraction directory
Acknowledgements
Thank you to Oleh Konko from 1seal for discovering and reporting this issue.
Other sources
malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 1.8.0 and prior to version 1.20.3, malcontent could be made to create symlinks outside the intended extraction directory when scanning a specially crafted tar or deb archive. The handleSymlink function received arguments in the wrong order, causing the symlink target to be used as the symlink location. Additionally, symlink targets were not validated to ensure they resolved within the extraction directory. Version 1.20.3 introduces fixes that swap handleSymlink arguments, validate symlink location, and validate symlink targets that resolve within an extraction directory.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24846?
CVE-2026-24846 is categorized as a high severity vulnerability due to its potential to create symlinks outside the intended extraction directory.
How do I fix CVE-2026-24846?
To fix CVE-2026-24846, upgrade to malcontent version 1.20.3 or higher.
What types of archives are affected by CVE-2026-24846?
CVE-2026-24846 affects tar and deb archive files that are scanned by malcontent.
Who is impacted by CVE-2026-24846?
Users of the malcontent package versions between 1.8.0 and 1.20.3 are impacted by CVE-2026-24846.
What is the nature of the vulnerability described in CVE-2026-24846?
The vulnerability in CVE-2026-24846 allows malcontent to create symlinks outside the designated extraction directory due to incorrect handling of function arguments.