<Vulnerability name="CVE-2026-45491">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-06-09T17:04:44</PublicDate>
    <Bugzilla id="2487164" url="https://bugzilla.redhat.com/show_bug.cgi?id=2487164" xml:lang="en:us">
dotnet: .NET: Local file tampering via link following vulnerability
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>6.2</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-59</CWE>
    <Details xml:lang="en:us" source="Mitre">
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in .NET's System.Formats.Tar library. When extracting a specially crafted TAR archive containing symbolic links, the TarFile.ExtractToDirectory() method may incorrectly follow those links and write files outside the intended extraction directory. An attacker could exploit this issue to create or overwrite files in locations accessible to the extracting process, potentially leading to unauthorized file modification.
    </Details>
    <Statement xml:lang="en:us">
This vulnerability affects .NET's TAR archive extraction functionality. Red Hat Product Security has assessed this issue as a Moderate severity vulnerability.

The flaw occurs in System.Formats.Tar when processing TAR archives containing symbolic links. During extraction, the TarFile.ExtractToDirectory() method may incorrectly follow symlink paths and write files outside the intended extraction directory.

Successful exploitation requires a vulnerable application to process a specially crafted TAR archive. An attacker could use this behavior to create or overwrite files in locations accessible to the extracting process, potentially affecting system or application integrity.

The vulnerability is a symlink path traversal issue that results in unauthorized file modification outside the designated extraction directory. The primary security impact is integrity compromise through arbitrary file writes.
    </Statement>
    <Mitigation xml:lang="en:us">
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.
    </Mitigation>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:10.2">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <ReleaseDate>2026-06-10T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25111">RHSA-2026:25111</Advisory>
        <Package name="dotnet8.0">dotnet8.0-0:8.0.128-1.el10_2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:10.2">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <ReleaseDate>2026-06-10T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25112">RHSA-2026:25112</Advisory>
        <Package name="dotnet9.0">dotnet9.0-0:9.0.118-1.el10_2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:10.2">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <ReleaseDate>2026-06-10T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25115">RHSA-2026:25115</Advisory>
        <Package name="dotnet10.0">dotnet10.0-0:10.0.109-1.el10_2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux_eus:10.0">
        <ProductName>Red Hat Enterprise Linux 10.0 Extended Update Support</ProductName>
        <ReleaseDate>2026-06-22T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28007">RHSA-2026:28007</Advisory>
        <Package name="dotnet8.0">dotnet8.0-0:8.0.128-1.el10_0</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux_eus:10.0">
        <ProductName>Red Hat Enterprise Linux 10.0 Extended Update Support</ProductName>
        <ReleaseDate>2026-06-22T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28009">RHSA-2026:28009</Advisory>
        <Package name="dotnet9.0">dotnet9.0-0:9.0.118-1.el10_0</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <ReleaseDate>2026-06-10T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25110">RHSA-2026:25110</Advisory>
        <Package name="dotnet8.0">dotnet8.0-0:8.0.128-1.el8_10</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <ReleaseDate>2026-06-10T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25113">RHSA-2026:25113</Advisory>
        <Package name="dotnet9.0">dotnet9.0-0:9.0.118-1.el8_10</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <ReleaseDate>2026-06-10T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25114">RHSA-2026:25114</Advisory>
        <Package name="dotnet10.0">dotnet10.0-0:10.0.109-1.el8_10</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-06-11T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25220">RHSA-2026:25220</Advisory>
        <Package name="dotnet8.0">dotnet8.0-0:8.0.128-1.el9_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-06-11T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25221">RHSA-2026:25221</Advisory>
        <Package name="dotnet9.0">dotnet9.0-0:9.0.118-1.el9_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-06-11T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25222">RHSA-2026:25222</Advisory>
        <Package name="dotnet10.0">dotnet10.0-0:10.0.109-1.el9_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_e4s:9.4">
        <ProductName>Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions</ProductName>
        <ReleaseDate>2026-06-23T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28227">RHSA-2026:28227</Advisory>
        <Package name="dotnet8.0">dotnet8.0-0:8.0.128-1.el9_4</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus:9.6">
        <ProductName>Red Hat Enterprise Linux 9.6 Extended Update Support</ProductName>
        <ReleaseDate>2026-06-22T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28011">RHSA-2026:28011</Advisory>
        <Package name="dotnet8.0">dotnet8.0-0:8.0.128-1.el9_6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhel_eus:9.6">
        <ProductName>Red Hat Enterprise Linux 9.6 Extended Update Support</ProductName>
        <ReleaseDate>2026-06-29T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:28051">RHSA-2026:28051</Advisory>
        <Package name="dotnet9.0">dotnet9.0-0:9.0.118-1.el9_6</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-05-14T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:17527">RHSA-2026:17527</Advisory>
        <Package name="dotnet9-0-main">dotnet9-0-main-9.0.117-1.hum1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-06-17T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:26638">RHSA-2026:26638</Advisory>
        <Package name="dotnet10-0-main">dotnet10-0-main-10.0.109-1.hum1</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-06-18T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:26994">RHSA-2026:26994</Advisory>
        <Package name="dotnet8-0-main">dotnet8-0-main-8.0.128-1.hum1</Package>
    </AffectedRelease>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-45491
https://nvd.nist.gov/vuln/detail/CVE-2026-45491
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45491
    </References>
</Vulnerability>