{
  "document" : {
    "aggregate_severity" : {
      "namespace" : "https://access.redhat.com/security/updates/classification/",
      "text" : "Moderate"
    },
    "category" : "csaf_security_advisory",
    "csaf_version" : "2.0",
    "distribution" : {
      "text" : "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp" : {
        "label" : "WHITE",
        "url" : "https://www.first.org/tlp/"
      }
    },
    "lang" : "en",
    "notes" : [ {
      "category" : "summary",
      "text" : "An update for Red Hat Hardened Images RPMs is now available.",
      "title" : "Topic"
    }, {
      "category" : "general",
      "text" : "This update includes the following RPMs:\n\ntar:\n  * tar-1.35-9.1.hum1 (aarch64, x86_64)\n  * tar-1.35-9.1.hum1.src (src)\n\nSecurity Fix(es):\n\ntar:\n  * CVE-2026-18477",
      "title" : "Details"
    }, {
      "category" : "legal_disclaimer",
      "text" : "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
      "title" : "Terms of Use"
    } ],
    "publisher" : {
      "category" : "vendor",
      "contact_details" : "https://access.redhat.com/security/team/contact/",
      "issuing_authority" : "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name" : "Red Hat Product Security",
      "namespace" : "https://www.redhat.com"
    },
    "references" : [ {
      "category" : "self",
      "summary" : "https://access.redhat.com/errata/RHSA-2026:49361",
      "url" : "https://access.redhat.com/errata/RHSA-2026:49361"
    }, {
      "category" : "external",
      "summary" : "https://access.redhat.com/security/cve/CVE-2026-18477",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-18477"
    }, {
      "category" : "external",
      "summary" : "https://access.redhat.com/security/updates/classification/",
      "url" : "https://access.redhat.com/security/updates/classification/"
    }, {
      "category" : "external",
      "summary" : "https://images.redhat.com/",
      "url" : "https://images.redhat.com/"
    }, {
      "category" : "self",
      "summary" : "Canonical URL",
      "url" : "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_49361.json"
    } ],
    "title" : "Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update",
    "tracking" : {
      "current_release_date" : "2026-08-25T02:50:02+00:00",
      "generator" : {
        "date" : "2026-08-25T02:50:02+00:00",
        "engine" : {
          "name" : "Red Hat SDEngine",
          "version" : "5.3.16"
        }
      },
      "id" : "RHSA-2026:49361",
      "initial_release_date" : "2026-08-01T13:24:14+00:00",
      "revision_history" : [ {
        "date" : "2026-08-01T13:24:14+00:00",
        "number" : "1",
        "summary" : "Initial version"
      }, {
        "date" : "2026-08-22T06:15:42+00:00",
        "number" : "2",
        "summary" : "Last updated version"
      }, {
        "date" : "2026-08-25T02:50:02+00:00",
        "number" : "3",
        "summary" : "Last generated version"
      } ],
      "status" : "final",
      "version" : "3"
    }
  },
  "product_tree" : {
    "branches" : [ {
      "branches" : [ {
        "branches" : [ {
          "category" : "product_name",
          "name" : "Red Hat Hardened Images",
          "product" : {
            "name" : "Red Hat Hardened Images",
            "product_id" : "Red Hat Hardened Images",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:redhat:hummingbird:1"
            }
          }
        } ],
        "category" : "product_family",
        "name" : "Red Hat Hardened Images"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "tar-main@aarch64",
          "product" : {
            "name" : "tar-main@aarch64",
            "product_id" : "tar-main@aarch64",
            "product_identification_helper" : {
              "purl" : "pkg:rpm/redhat/tar@1.35-9.1.hum1?arch=aarch64&distro=hummingbird-20251124&repository_id=public-hummingbird-aarch64-rpms"
            }
          }
        } ],
        "category" : "architecture",
        "name" : "aarch64"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "tar-main@src",
          "product" : {
            "name" : "tar-main@src",
            "product_id" : "tar-main@src",
            "product_identification_helper" : {
              "purl" : "pkg:rpm/redhat/tar@1.35-9.1.hum1?arch=src&distro=hummingbird-20251124&repository_id=public-hummingbird-source-rpms"
            }
          }
        } ],
        "category" : "architecture",
        "name" : "src"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "tar-main@x86_64",
          "product" : {
            "name" : "tar-main@x86_64",
            "product_id" : "tar-main@x86_64",
            "product_identification_helper" : {
              "purl" : "pkg:rpm/redhat/tar@1.35-9.1.hum1?arch=x86_64&distro=hummingbird-20251124&repository_id=public-hummingbird-x86_64-rpms"
            }
          }
        } ],
        "category" : "architecture",
        "name" : "x86_64"
      } ],
      "category" : "vendor",
      "name" : "Red Hat"
    } ],
    "relationships" : [ {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "tar-main@aarch64 as a component of Red Hat Hardened Images",
        "product_id" : "Red Hat Hardened Images:tar-main@aarch64"
      },
      "product_reference" : "tar-main@aarch64",
      "relates_to_product_reference" : "Red Hat Hardened Images"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "tar-main@src as a component of Red Hat Hardened Images",
        "product_id" : "Red Hat Hardened Images:tar-main@src"
      },
      "product_reference" : "tar-main@src",
      "relates_to_product_reference" : "Red Hat Hardened Images"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "tar-main@x86_64 as a component of Red Hat Hardened Images",
        "product_id" : "Red Hat Hardened Images:tar-main@x86_64"
      },
      "product_reference" : "tar-main@x86_64",
      "relates_to_product_reference" : "Red Hat Hardened Images"
    } ]
  },
  "vulnerabilities" : [ {
    "acknowledgments" : [ {
      "names" : [ "Michał Majchrowicz", "Marcin Wyczechowski" ],
      "organization" : "AFINE Team"
    } ],
    "cve" : "CVE-2026-18477",
    "cwe" : {
      "id" : "CWE-367",
      "name" : "Time-of-check Time-of-use (TOCTOU) Race Condition"
    },
    "discovery_date" : "2026-07-31T10:48:52.898000+00:00",
    "ids" : [ {
      "system_name" : "Red Hat Bugzilla ID",
      "text" : "2509735"
    } ],
    "notes" : [ {
      "category" : "description",
      "text" : "A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.",
      "title" : "Vulnerability description"
    }, {
      "category" : "summary",
      "text" : "tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape",
      "title" : "Vulnerability summary"
    }, {
      "category" : "other",
      "text" : "This issue affects GNU tar incremental backup and restore (-g/-G). A local attacker who can write to content included in an incremental backup, and who can also access the system where that backup is later restored, may cause the restore to create, rename, or overwrite paths outside the intended extraction directory via a TOCTOU race in dumpdir 'X' handling. The attacker does not need to craft or alter the archive, and extracting it into a fresh directory does not mitigate the issue. Red Hat is assessing impact for the tar package in supported products.",
      "title" : "Statement"
    }, {
      "category" : "general",
      "text" : "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
      "title" : "CVSS score applicability"
    } ],
    "product_status" : {
      "fixed" : [ "Red Hat Hardened Images:tar-main@aarch64", "Red Hat Hardened Images:tar-main@src", "Red Hat Hardened Images:tar-main@x86_64" ]
    },
    "references" : [ {
      "category" : "self",
      "summary" : "Canonical URL",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-18477"
    }, {
      "category" : "external",
      "summary" : "RHBZ#2509735",
      "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2509735"
    }, {
      "category" : "external",
      "summary" : "https://www.cve.org/CVERecord?id=CVE-2026-18477",
      "url" : "https://www.cve.org/CVERecord?id=CVE-2026-18477"
    }, {
      "category" : "external",
      "summary" : "https://nvd.nist.gov/vuln/detail/CVE-2026-18477",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-18477"
    } ],
    "release_date" : "2026-07-31T00:00:00+00:00",
    "remediations" : [ {
      "category" : "vendor_fix",
      "date" : "2026-08-01T13:24:14+00:00",
      "details" : "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
      "product_ids" : [ "Red Hat Hardened Images:tar-main@aarch64", "Red Hat Hardened Images:tar-main@src", "Red Hat Hardened Images:tar-main@x86_64" ],
      "restart_required" : {
        "category" : "none"
      },
      "url" : "https://access.redhat.com/errata/RHSA-2026:49361"
    }, {
      "category" : "workaround",
      "details" : "Do not perform incremental restores (-G/-g) from untrusted archives. Avoid restoring incremental backups on systems where untrusted users have shell access,​ perform restoration only on systems inaccessible to users.",
      "product_ids" : [ "Red Hat Hardened Images:tar-main@aarch64", "Red Hat Hardened Images:tar-main@src", "Red Hat Hardened Images:tar-main@x86_64" ]
    } ],
    "scores" : [ {
      "cvss_v3" : {
        "attackComplexity" : "HIGH",
        "attackVector" : "LOCAL",
        "availabilityImpact" : "NONE",
        "baseScore" : 4.4,
        "baseSeverity" : "MEDIUM",
        "confidentialityImpact" : "NONE",
        "integrityImpact" : "HIGH",
        "privilegesRequired" : "LOW",
        "scope" : "UNCHANGED",
        "userInteraction" : "REQUIRED",
        "vectorString" : "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N",
        "version" : "3.1"
      },
      "products" : [ "Red Hat Hardened Images:tar-main@aarch64", "Red Hat Hardened Images:tar-main@src", "Red Hat Hardened Images:tar-main@x86_64" ]
    } ],
    "threats" : [ {
      "category" : "impact",
      "details" : "Moderate"
    } ],
    "title" : "tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape"
  } ]
}