REDHAT-BUG-2509735: Medium severity GNU tar vulnerability
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2509735?
The severity of REDHAT-BUG-2509735 is classified as medium with a score of 4.
What does REDHAT-BUG-2509735 vulnerability involve?
REDHAT-BUG-2509735 involves a TOCTOU vulnerability in GNU tar's incremental dumpdir rename handling.
Who can exploit REDHAT-BUG-2509735?
A local attacker with write access to a directory being backed up can exploit REDHAT-BUG-2509735.
How can I mitigate REDHAT-BUG-2509735?
To mitigate REDHAT-BUG-2509735, limit write access to directories used by GNU tar during backup operations.
What software is affected by REDHAT-BUG-2509735?
The affected software by REDHAT-BUG-2509735 is GNU tar.