Red Hat Enterprise Linux: race condition
Medium4.4CVE-2026-18477 · Published Aug 3, 2026 · updated Sep 22, 2026
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 6 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-367
- www.cve.org/CVERecord?id=CVE-2026-18477
- nvd.nist.gov/vuln/detail/CVE-2026-18477
- access.redhat.com/errata/RHSA-2026:49361
- access.redhat.com/errata/RHSA-2026:61581
- access.redhat.com/errata/RHSA-2026:61586
- access.redhat.com/errata/RHSA-2026:61783
- access.redhat.com/errata/RHSA-2026:66018
- access.redhat.com/errata/RHSA-2026:70390
- access.redhat.com/security/cve/CVE-2026-18477
- bugzilla.redhat.com/show_bug.cgi?id=2509735
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 3 | Red Hat 389 Directory Server: improper authentication | Medium5.4 | No fix yet |
| Aug 3 | Red Hat GNU tar.: link following | Medium4.4 | No fix yet |
| Aug 3 | Red Hat SSSD: out-of-bounds read | Medium5.5 | No fix yet |
| Aug 3 | Red Hat GIMP: stack buffer overflow | Medium5.5 | No fix yet |
| Aug 3 | Red Hat GIMP. A remote attacker: out-of-bounds write | Medium5.5 | No fix yet |
| Aug 2 | Red Hat user creation: information disclosure | Medium6.6 | No fix yet |