Executive brief
The sos package includes a cleanup utility (sos clean) used to sanitize system diagnostic data before sharing with support teams. An attacker can craft a malicious archive file that, when processed by sos clean, writes files to arbitrary locations on the system with root privileges, potentially compromising system integrity or enabling unauthorized access.
Technical details
The vulnerability is a path traversal flaw (CWE-59) in sos clean's tar extraction logic, where symlink and hardlink targets within archive files are not properly validated before extraction. An attacker can craft a malicious tar archive containing symlinks or hardlinks pointing to sensitive system paths (/etc/passwd, /root/.ssh, etc.) that, when extracted, write or overwrite files at arbitrary locations. The attack requires local access and user interaction to process the crafted archive, but succeeds with the privileges of the sos clean process—typically root. A patch is available via upstream pull request #4461.
Affected products
- Red Hat sos <unknown
Timeline
- 2026-08-25: disclosed
- other: Upstream PR #4461 available for patching