CVE-2026-82331

Description

A flaw was found in the tar source plugin of Apache BuildStream. This improper link resolution vulnerability, also known as 'link following', allows a remote attacker to write arbitrary files on the host system. By crafting malicious source tarballs containing symlinks, an attacker can exploit this flaw during source fetching to execute code or escalate privileges with the permissions of the user running BuildStream.

Statement

This vulnerability is assessed as Moderate severity because exploitation requires a user to explicitly fetch an untrusted archive, and any resultant file modification remains strictly confined to the access permissions of the invoking account. Apache BuildStream is not included or supported in Red Hat Enterprise Linux, limiting exposure to community distributions. Additionally, environments executing on Python 3.12 or newer inherently prevent this directory traversal through native archive extraction filters.

Understanding the Weakness (CWE)

Confidentiality,Integrity,Access Control

Technical Impact: Read Files or Directories; Modify Files or Directories; Bypass Protection Mechanism

An attacker may be able to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. If the files are used for a security mechanism then an attacker may be able to bypass the mechanism.

Other

Technical Impact: Execute Unauthorized Code or Commands

Windows simple shortcuts, sometimes referred to as soft links, can be exploited remotely since a ".LNK" file can be uploaded like a normal file. This can enable remote execution.

Frequently Asked Questions

Want to get errata notifications? Sign up here.