Local file overwrite by extracting a malicious tar archive
Fixed in: go.podman.io/buildah/copier 1.43.4 / 1.45.1
details
- Finding IDs
- F-BUILDAH-SYMLINK-001
- CVE
- CVE-2026-79705
- GHSA
- GHSA-3528-5p26-cf44
- Status
- patched
- Fixed in
- go.podman.io/buildah/copier 1.43.4 / 1.45.1
- Recorded credit
- reporter: Oleh Konko / @1seal (alongside other reporters)
- Note
- GHSA-3528-5p26-cf44: malicious tar extraction can overwrite local files when external consumers call buildah/copier as non-root or on non-Linux systems. Users of Buildah itself are not affected. Fixed via commit a88128d47cb3f3fcbd9e874270c22271b73eb30d. The legacy github.com/containers/buildah/copier module has no patched versions; migrate to go.podman.io/buildah/copier.
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- Local file overwrite by extracting a malicious tar archive
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-BUILDAH-SYMLINK-001: File / path escapes. Tar extraction permits writes outside the intended directory. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-BUILDAH-SYMLINK-001
Security area (1seal assessment): Authorization. Tar extraction can overwrite files outside the intended destination; this is a filesystem access boundary, not a registry-pull defect. Reviewed 21 Sep 2026.