{"id":"CVE-2026-11940","title":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's…","summary":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's…","severity":"high","cwe":["CWE-22","CWE-59"],"published":"2026-06-23","updated":"2026-08-06","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","references":[{"url":"https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","label":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","label":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","label":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","label":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","label":"cna@python.org"},{"url":"https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","label":"cna@python.org"},{"url":"https://github.com/python/cpython/issues/151558","label":"cna@python.org"},{"url":"https://github.com/python/cpython/pull/151559","label":"cna@python.org"},{"url":"https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/","label":"cna@python.org"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11940.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-11940"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491848"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-11940"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940"},{"url":"https://access.redhat.com/errata/RHSA-2026:63024"},{"url":"https://access.redhat.com/errata/RHSA-2026:58902"},{"url":"https://access.redhat.com/errata/RHSA-2026:58928"},{"url":"https://access.redhat.com/errata/RHSA-2026:56219"},{"url":"https://access.redhat.com/errata/RHSA-2026:58971"},{"url":"https://access.redhat.com/errata/RHSA-2026:64816"},{"url":"https://access.redhat.com/errata/RHSA-2026:64806"},{"url":"https://access.redhat.com/errata/RHSA-2026:62809"},{"url":"https://access.redhat.com/errata/RHSA-2026:63117"},{"url":"https://access.redhat.com/errata/RHSA-2026:54268"},{"url":"https://access.redhat.com/errata/RHSA-2026:59009"},{"url":"https://access.redhat.com/errata/RHSA-2026:58901"},{"url":"https://access.redhat.com/errata/RHSA-2026:54760"},{"url":"https://access.redhat.com/errata/RHSA-2026:38018"},{"url":"https://access.redhat.com/errata/RHSA-2026:38017"},{"url":"https://access.redhat.com/errata/RHSA-2026:38090"},{"url":"https://access.redhat.com/errata/RHSA-2026:38091"},{"url":"https://access.redhat.com/errata/RHSA-2026:54534"},{"url":"https://access.redhat.com/errata/RHSA-2026:58981"},{"url":"https://access.redhat.com/errata/RHSA-2026:66018"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.0075,"epssPercentile":0.53023,"ingestedAt":"2026-08-06T19:02:50.068Z","vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","affected":["enterprise_linux 8","enterprise_linux 9","enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_aus_v_8_6","enterprise_linux_appstream_eus_extension_v_8_6","enterprise_linux_appstream_e4s_v_8_8","enterprise_linux_appstream_tus_v_8_8","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","enterprise_linux_baseos_eus_v_10_0","enterprise_linux_baseos_v_10","enterprise_linux_baseos_v_8","enterprise_linux_baseos_aus_v_8_6","enterprise_linux_baseos_eus_extension_v_8_6","enterprise_linux_baseos_e4s_v_8_8","enterprise_linux_baseos_tus_v_8_8","enterprise_linux_baseos_v_9","enterprise_linux_codeready_linux_builder_eus_v_10_0","enterprise_linux_codeready_linux_builder_v_10","enterprise_linux_crb_v_8","codeready_linux_builder_eus_v_9_6","enterprise_linux_codeready_linux_builder_v_9","discovery 2","hardened_images","update_infrastructure 5"],"patched":["enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_aus_v_8_6","enterprise_linux_appstream_eus_extension_v_8_6","enterprise_linux_appstream_e4s_v_8_8","enterprise_linux_appstream_tus_v_8_8","enterprise_linux_appstream_e4s_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","enterprise_linux_baseos_eus_v_10_0","enterprise_linux_baseos_v_10","enterprise_linux_baseos_v_8","enterprise_linux_baseos_aus_v_8_6","enterprise_linux_baseos_eus_extension_v_8_6","enterprise_linux_baseos_e4s_v_8_8","enterprise_linux_baseos_tus_v_8_8","enterprise_linux_baseos_v_9","enterprise_linux_codeready_linux_builder_eus_v_10_0","enterprise_linux_codeready_linux_builder_v_10","enterprise_linux_crb_v_8","codeready_linux_builder_eus_v_9_6","enterprise_linux_codeready_linux_builder_v_9","discovery 2","hardened_images","update_infrastructure 5"],"cvss":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","cvssSource":"vendor","slug":"CVE-2026-11940","body":"## Overview\n\ntarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:63024** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux BaseOS EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0) · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63024)\n- **RHSA-2026:58902** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58902)\n- **RHSA-2026:58928** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58928)\n- **RHSA-2026:56219** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux BaseOS (v. 8) · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:56219)\n- **RHSA-2026:58971** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:58971)\n- **RHSA-2026:64816** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6), Red Hat Enterprise Linux BaseOS AUS (v.8.6), Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64816)\n- **RHSA-2026:64806** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8), Red Hat Enterprise Linux BaseOS E4S (v.8.8), Red Hat Enterprise Linux BaseOS TUS (v.8.8) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64806)\n- **RHSA-2026:62809** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62809)\n- **RHSA-2026:63117** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat CodeReady Linux Builder EUS (v.9.6) · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63117)\n- **RHSA-2026:54268** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54268)\n- **RHSA-2026:59009** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59009)\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11940.json)","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":40.2,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[{"seq":4936,"id":"CVE-2026-11940","ts":1788887217709,"field":"cvss","old":null,"new":"7.3"},{"seq":4935,"id":"CVE-2026-11940","ts":1788887217709,"field":"severity","old":"none","new":"high"},{"seq":3819,"id":"CVE-2026-11940","ts":1788886348028,"field":"cvss","old":"7.3","new":null},{"seq":3818,"id":"CVE-2026-11940","ts":1788886348028,"field":"severity","old":"high","new":"none"},{"seq":3233,"id":"CVE-2026-11940","ts":1788883135942,"field":"cvss","old":null,"new":"7.3"},{"seq":3232,"id":"CVE-2026-11940","ts":1788883135942,"field":"severity","old":"none","new":"high"}]}