REDHAT-BUG-2548611: Medium severity Busybox Busybox vulnerability
A flaw was found in busybox. The tar applet defers creation of symlink and hardlink entries whose targets look unsafe (absolute paths, hardlinks, or targets containing '..') until after all archive members have been processed, in order to avoid a same-archive time-of-check-to-time-of-use issue. However, when those deferred links are finally created, the code performs the underlying symlink() or link() system call directly, without re-validating that the resolved destination parent remains inside the extraction directory. By chaining an immediately-created symlink with a deferred symlink whose target is exactly '..' (a value not caught by the separate prefix-based sanitizer applied to member names, which only strips leading '../' and embedded '/../' sequences), an attacker can make a path that appears to be inside the extraction directory resolve outside it once the deferred link is created. Combined with a deferred hardlink in the same archive, this creates a new file outside the extraction directory; reusing the same destination directory across two archives allows an existing external file to be deleted and replaced with attacker-controlled content, including attacker-controlled ownership and permissions for privileged extraction, since the second archive's replacement member is an ordinary file entry (not a hardlink) and is subject to busybox tar's normal chown()/chmod() restoration from the archive header. The one-archive hardlink primitive requires the internal source file and the external target to reside on the same filesystem; the two-archive primitive requires the extraction directory to be reused across two extraction invocations.