CVE-2026-105712

Public on 2026-10-05
Modified on 2026-10-08
Description
gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.
Severity
Low severity
Low
See what this means
CVSS v3 Base Score
3.6
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core gnupg2 Not Affected
Amazon Linux 2023 gnupg2 Pending Fix
Amazon Linux 2027 Preview gnupg2 Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L