Beveiligingsadvies

CVE-2026-79705

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-15 16:23:26
Laatst bijgewerkt 2026-09-15 17:58:45
Toegewezen door redhat
CVSS-score 4.5
Status PUBLISHED

Beschrijving

A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Buildah itself uses chroot hardening and is not affected.