云虫漏洞库

CVE-2026-79655 - A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issue during tar extraction, where symlink and hardlink targets are not properly validated. This enables the attacker to write files to arbitrary locations on the system with the privileges of the sos clean process, which often runs as root. - 漏洞详情

漏洞编号:CVE-2026-79655

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-79655

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-59

发布/更新时间:2026-08-25 / 2026-08-28

漏洞描述

A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issue during tar extraction, where symlink and hardlink targets are not properly validated. This enables the attacker to write files to arbitrary locations on the system with the privileges of the sos clean process, which often runs as root.

相关链接

相关漏洞

« 返回首页