CVE-2026-85731

Description

A flaw was found in oras-go, a Go library for managing OCI (Open Container Initiative) artifacts. A remote attacker can exploit a symlink-chain bypass vulnerability during tar extraction of OCI layers. This allows a malicious archive to create or overwrite any file writable by the process outside the intended working directory. Successful exploitation may lead to arbitrary code execution.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Mitigation

To mitigate this issue, Red Hat recommends avoiding the processing of untrusted OCI artifacts with oras-go. If processing untrusted artifacts is unavoidable, ensure that the application utilizing oras-go operates within a restricted and isolated environment, such as a container or a dedicated user with minimal privileges, to limit the potential impact of arbitrary file writes and code execution.

Understanding the Weakness (CWE)

Confidentiality,Integrity,Access Control

Technical Impact: Read Files or Directories; Modify Files or Directories; Bypass Protection Mechanism

An attacker may be able to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. If the files are used for a security mechanism then an attacker may be able to bypass the mechanism.

Other

Technical Impact: Execute Unauthorized Code or Commands

Windows simple shortcuts, sometimes referred to as soft links, can be exploited remotely since a ".LNK" file can be uploaded like a normal file. This can enable remote execution.

Frequently Asked Questions

Want to get errata notifications? Sign up here.