{"id":"CVE-2026-79699","title":"A flaw was found in the containers/storage library","summary":"A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by st…","severity":"medium","cvss":4.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","cwe":["CWE-59"],"vendor":"Red Hat","product":"ansible-automation-platform-24/eda-controller-rhel8","affected":["ansible-automation-platform-24/eda-controller-rhel8 (all versions)","ansible-automation-platform-25/eda-controller-rhel8 (all versions)","ansible-automation-platform-26/eda-controller-rhel9 (all versions)","ansible-automation-platform-27/eda-controller-rhel9 (all versions)","python3.11-podman (all versions)","python3.12-podman (all versions)","python3x-podman (all versions)","python-podman (all versions)","buildah (all versions)","podman (all versions)","skopeo (all versions)","buildah (all versions)","podman (all versions)","skopeo (all versions)","buildah (all versions)","podman (all versions)","python-podman (all versions)","rhel9/buildah (all versions)","rhel9/podman (all versions)","rhel9/skopeo (all versions)","skopeo (all versions)","buildah (all versions)","podman (all versions)","skopeo (all versions)","podman (all versions)","skopeo (all versions)","devspaces/udi-base-rhel10 (all versions)","devspaces/udi-base-rhel9 (all versions)","devspaces/udi-rhel9 (all versions)","container-native-virtualization/ocp-virt-validation-checkup-rhel9 (all versions)","quay/quay-builder-rhel8 (all versions)","quay/quay-builder-rhel9 (all versions)"],"published":"2026-09-15","updated":"2026-09-17","sourceUpdated":"2026-09-17T19:17:03.080","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79699","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-79699","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2523408","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-79699.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-79699"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79699"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-17T18:29:49.557906Z"},"epss":0.0013,"epssPercentile":0.02973,"ingestedAt":"2026-09-15T16:40:03.397Z","slug":"CVE-2026-79699","body":"## Overview\n\nA flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by storage/pkg/archive.UnpackLayer, ApplyLayer, or ApplyUncompressedLayer.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, … · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-79699.json)","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":24.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}