REDHAT-BUG-2548611: Medium severity Busybox Busybox vulnerability

Published Oct 9, 2026
·
Updated

A flaw was found in busybox. The tar applet defers creation of symlink and hardlink entries whose targets look unsafe (absolute paths, hardlinks, or targets containing '..') until after all archive members have been processed, in order to avoid a same-archive time-of-check-to-time-of-use issue. However, when those deferred links are finally created, the code performs the underlying symlink() or link() system call directly, without re-validating that the resolved destination parent remains inside the extraction directory. By chaining an immediately-created symlink with a deferred symlink whose target is exactly '..' (a value not caught by the separate prefix-based sanitizer applied to member names, which only strips leading '../' and embedded '/../' sequences), an attacker can make a path that appears to be inside the extraction directory resolve outside it once the deferred link is created. Combined with a deferred hardlink in the same archive, this creates a new file outside the extraction directory; reusing the same destination directory across two archives allows an existing external file to be deleted and replaced with attacker-controlled content, including attacker-controlled ownership and permissions for privileged extraction, since the second archive's replacement member is an ordinary file entry (not a hardlink) and is subject to busybox tar's normal chown()/chmod() restoration from the archive header. The one-archive hardlink primitive requires the internal source file and the external target to reside on the same filesystem; the two-archive primitive requires the extraction directory to be reused across two extraction invocations.

Affected Software

1 affected component
Busybox Busybox

Event History

Oct 9, 2026
Data Sourced
via Red Hat·02:14 PM
DescriptionSeverityAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203