CVE-2026-42497Disclosure(archive\ / \)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode. A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59CWE-732

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • \

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
\

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-26: 2Technical Details · 2026-05-26: 105-26
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets5 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN Archive::Tar CVE-2026-42496: Extract symlinks with attacker controlled targets outside the extraction directory https://www.openwall.com/lists/oss-security/2026/05/26/2 CVE-2026-42497: ditto for hardlinks https://www.openwall.com/lists/oss-security/2026/05/26/3 CVE-2026-9538: Memory exhaustion via tar header https://www.openwall.com/lists/oss-security/2026/05/26/4

    Post summary

    Three new CVEs in the Perl CPAN Archive::Tar module are disclosed, detailing symlink and hardlink extraction weaknesses and a memory‑exhaustion issue via tar headers, with links to Openwall discussion posts.

    01051643
    4.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42497 CVE-2026-42496 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42497 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The text merely lists two CVE identifiers and provides links to vulnerability details and scanning alerts, without additional technical or exploit information.

    0000078
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apparchive\\tar_project--

Explore more