REDHAT-BUG-2439040: Path Traversal

Published Feb 11, 2026
·
Updated

Affects: BusyBox v1.36.1 and v1.37.0 (likely affects earlier versions too) CVSS: 9.3 (CRITICAL) Component: dataextractall.c in tar extraction - hardlink and symlink handling

Description: Hardlink entries in tar archives are created without validation of the linktarget path. This allows modification of files outside the extraction directory and bypasses existing path traversal mitigations. This vulnerability has higher impact than the path traversal issue as it does not rely on relative paths or the current working directory.

Technical Details: - Hardlink entries can point to absolute paths like /etc/passwd - Symlink entries suffer from the same root cause (missing linktarget validation) - When extraction is performed with elevated privileges, attackers can modify critical system files

Impact: Arbitrary file modification outside extraction directory, privilege escalation when combined with elevated extraction permissions, bypass of path traversal protections.

Note: While hardlinks and symlinks share the same root cause (missing linktarget validation), I'm requesting a single CVE for this issue.

Affected Software

1 affected component
busybox>=1.36.1<1.37.0

Event History

Feb 11, 2026
Data Sourced
via Red Hat·06:13 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2439040?

The severity of REDHAT-BUG-2439040 is rated as critical with a CVSS score of 9.3.

2

How do I fix REDHAT-BUG-2439040?

To address REDHAT-BUG-2439040, upgrade BusyBox to versions later than 1.37.0.

3

Which versions of BusyBox are affected by REDHAT-BUG-2439040?

REDHAT-BUG-2439040 affects BusyBox versions 1.36.1 and 1.37.0, likely impacting earlier versions as well.

4

What is the nature of the vulnerability in REDHAT-BUG-2439040?

The vulnerability in REDHAT-BUG-2439040 involves inadequate validation of hardlink entries in tar archives.

5

Can this vulnerability in REDHAT-BUG-2439040 lead to security risks?

Yes, the vulnerability can potentially allow attackers to modify files without proper user permissions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203