Junglewise Threat Intelligence

CVE-2026-42497: Perl Archive::Tar path traversal via hardlink extraction

CVE-2026-42497 · Severity: info · CVSS 0 · Published 2026-05-26

Vendors: Perl.

Executive brief

Archive::Tar is a Perl library used to create and extract tar archives. A security flaw in versions before 3.08 allows a malicious archive to create "hardlinks" to files outside of the intended extraction folder. This could allow an attacker to overwrite sensitive system files or change their permissions, potentially leading to unauthorized data modification or system instability.

Technical details

A vulnerability exists in Archive::Tar's `_make_special_file()` function where the tar header's `linkname` is passed directly to the `link()` system call without validation against absolute paths or directory traversal (..) segments. This allows an attacker to create a hardlink that shares an inode with a victim file outside the extraction directory. Because the extraction process subsequently applies `chmod`, `chown`, and `utime` operations to the extracted file (which now shares an inode with the victim file), an attacker can modify the permissions and ownership of arbitrary files. The fix, introduced in version 3.08, implements validation for symlinks and hardlinks when not in insecure extraction mode.

Affected products

  • Perl Archive::Tar before 3.08

Timeline

  • 2026-05-26: advisory: NVD published date
  • 2026-05-22: patched: Version 3.08 released with fix

References