mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-30 22:11:59 -09:00
Based on the work of the OpenEmbedded community. This commit patches the
following vulnerabilities:
- CVE-2026-26157:
A flaw was found in BusyBox. Incomplete path sanitization in its
archive extraction utilities allows an attacker to craft malicious
archives that when extracted, and under specific conditions, may write
to files outside the intended directory. This can lead to arbitrary
file overwrite, potentially enabling code execution through the
modification of sensitive system files.
https://www.cve.org/CVERecord?id=CVE-2026-26157
- CVE-2026-26158:
A flaw was found in BusyBox. This vulnerability allows an attacker to
modify files outside of the intended extraction directory by crafting
a malicious tar archive containing unvalidated hardlink or symlink
entries. If the tar archive is extracted with elevated privileges,
this flaw can lead to privilege escalation, enabling an attacker to
gain unauthorized access to critical system files.
https://www.cve.org/CVERecord?id=CVE-2026-26158
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
(alternative to commit 5a27004cff)
Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
39 lines
1.6 KiB
Diff
39 lines
1.6 KiB
Diff
From 599f5dd8fac390c18b79cba4c14c334957605dae Mon Sep 17 00:00:00 2001
|
|
From: Radoslav Kolev <radoslav.kolev@suse.com>
|
|
Date: Mon, 16 Feb 2026 11:50:04 +0200
|
|
Subject: [PATCH] tar: only strip unsafe components from hardlinks, not
|
|
symlinks
|
|
|
|
commit 3fb6b31c7 introduced a check for unsafe components in
|
|
tar archive hardlinks, but it was being applied to symlinks too
|
|
which broke "Symlinks and hardlinks coexist" tar test.
|
|
|
|
Signed-off-by: Radoslav Kolev <radoslav.kolev@suse.com>
|
|
Signed-off-by: Denys Vlasenko <vda.linux@googlemail.com>
|
|
|
|
CVE: CVE-2026-26157
|
|
CVE: CVE-2026-26158
|
|
Upstream: https://git.busybox.net/busybox/commit/?id=599f5dd8fac390c18b79cba4c14c334957605dae
|
|
Upstream: https://gogs.librecmc.org/OWEALS/busybox/commit/599f5dd8fac390c18b79cba4c14c334957605dae
|
|
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
|
|
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
|
|
---
|
|
archival/libarchive/get_header_tar.c | 2 +-
|
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
|
|
diff --git a/archival/libarchive/get_header_tar.c b/archival/libarchive/get_header_tar.c
|
|
index 1c40ece..606d806 100644
|
|
--- a/archival/libarchive/get_header_tar.c
|
|
+++ b/archival/libarchive/get_header_tar.c
|
|
@@ -455,7 +455,7 @@ char FAST_FUNC get_header_tar(archive_handle_t *archive_handle)
|
|
|
|
/* Everything up to and including last ".." component is stripped */
|
|
strip_unsafe_prefix(file_header->name);
|
|
- if (file_header->link_target) {
|
|
+ if (file_header->link_target && !S_ISLNK(file_header->mode)) {
|
|
/* GNU tar 1.34 examples:
|
|
* tar: Removing leading '/' from hard link targets
|
|
* tar: Removing leading '../' from hard link targets
|
|
--
|
|
2.50.1
|