CVE-2026-82331
Description
A flaw was found in the tar source plugin of Apache BuildStream. This improper link resolution vulnerability, also known as 'link following', allows a remote attacker to write arbitrary files on the host system. By crafting malicious source tarballs containing symlinks, an attacker can exploit this flaw during source fetching to execute code or escalate privileges with the permissions of the user running BuildStream.
Statement
This vulnerability is assessed as Moderate severity because exploitation requires a user to explicitly fetch an untrusted archive, and any resultant file modification remains strictly confined to the access permissions of the invoking account. Apache BuildStream is not included or supported in Red Hat Enterprise Linux, limiting exposure to community distributions. Additionally, environments executing on Python 3.12 or newer inherently prevent this directory traversal through native archive extraction filters.
Understanding the Weakness (CWE)
Confidentiality,Integrity,Access Control
Technical Impact: Read Files or Directories; Modify Files or Directories; Bypass Protection Mechanism
An attacker may be able to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. If the files are used for a security mechanism then an attacker may be able to bypass the mechanism.
Other
Technical Impact: Execute Unauthorized Code or Commands
Windows simple shortcuts, sometimes referred to as soft links, can be exploited remotely since a ".LNK" file can be uploaded like a normal file. This can enable remote execution.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.