CVE-2026-105712
ADVISORY - nistSummary
gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.
Common Weakness Enumeration (CWE)
ADVISORY - nist
UNIX Symbolic Link (Symlink) Following
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-105712
EXPLOITABILITY SCORE
1
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
3.6lowDebian
CREATED
UPDATED
ADVISORY IDCVE-2026-105712
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-