Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4002 articles · 197512 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-79655EXPLOITED
red hat · red hat enterprise linux

Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write

Description

A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issue during tar extraction, where symlink and hardlink targets are not properly validated. This enables the attacker to write files to arbitrary locations on the system with the privileges of the sos clean process, which often runs as root.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

References

  • https://access.redhat.com/security/cve/CVE-2026-79655(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2523363(issue-tracking, x_refsource_REDHAT)
  • https://github.com/sosreport/sos/issues/4460
  • https://github.com/sosreport/sos/pull/4461

Related News (1 articles)

Tier C
VulDB13h ago
CVE-2026-79655 | Red Hat Enterprise Linux up to 10 Tar Extraction path traversal
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-59
PublishedAug 25, 2026
Last enriched12h ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score56
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-78367EXP
Rpm: rpmbuild gettarspec() crafted tar member name → macro injection
Trending: 58
NONECVE-2026-78465EXP
Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit
Trending: 58
NONECVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
Trending: 54
CRITICALCVE-2026-19685EXP
Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for cve-2025-9615)
Trending: 53
NONECVE-2026-14613EXP
Keycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses hidden group metadata without group view permission
Trending: 50

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 25, 2026
Discovered by ZDM
Aug 25, 2026
Actively Exploited
Aug 25, 2026
Exploit Available
Aug 25, 2026