REDHAT-BUG-2547419: Medium severity Openshift Source-to-Image vulnerability

Published Oct 7, 2026
·
Updated

A flaw was found in openshift/source-to-image's paranoid tar extraction mode (NewParanoid). The extractLink() function in pkg/tar/tar.go validates that a symlink target stays inside the extraction directory by computing a sanitized path using filepath.Clean(filepath.Join(dest, "..", source)), but then creates the actual symlink using the raw, unvalidated header.Linkname via os.Symlink(source, dest). For relative symlink traversals this check works correctly because filepath.Join resolves ".." components. However, for absolute Linkname values (e.g. "/etc/passwd"), Go's filepath.Join does not re-root, so the sanitized path folds harmlessly under the jail directory and passes the check, while the actual symlink points to the attacker-specified absolute host path. This bypasses the security boundary introduced to fix CVE-2018-1103. The paranoid mode is used by s2i's primary build strategy, including paths that extract tar streams produced by attacker-controlled builder image scripts (save-artifacts, assemble). A malicious builder image can plant symlinks pointing to arbitrary absolute host paths outside the sandbox directory.

Affected Software

1 affected component
Openshift Source-to-Image

Event History

Oct 7, 2026
Data Sourced
via Red Hat·12:32 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which Source-to-Image workflows are exposed?

The issue affects use of the paranoid tar extraction mode (NewParanoid), which is used by s2i's primary build strategy. This includes extraction of tar streams produced by builder-image scripts such as save-artifacts and assemble.

2

What does an attacker need to exploit this issue?

An attacker needs control over a builder image or its scripts so they can produce a tar stream containing a symlink with an absolute target path. The vulnerable extraction path can then create that symlink pointing outside the sandbox directory.

3

What is the practical impact of a successful exploit?

A malicious builder image can plant symlinks to arbitrary absolute host paths outside the intended extraction directory. The validation checks a sanitized path, but symlink creation uses the original unvalidated link target.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203