---
id: CVE-2026-79699
title: A flaw was found in the containers/storage library
summary: >-
  A flaw was found in the containers/storage library. A crafted tar archive
  containing a malicious whiteout header (e.g. victim/.wh.) can cause the
  extraction destination directory to be replaced with an arbitrary file when
  processed by st…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'
cwe:
  - CWE-59
vendor: Red Hat
product: ansible-automation-platform-24/eda-controller-rhel8
affected:
  - ansible-automation-platform-24/eda-controller-rhel8 (all versions)
  - ansible-automation-platform-25/eda-controller-rhel8 (all versions)
  - ansible-automation-platform-26/eda-controller-rhel9 (all versions)
  - ansible-automation-platform-27/eda-controller-rhel9 (all versions)
  - python3.11-podman (all versions)
  - python3.12-podman (all versions)
  - python3x-podman (all versions)
  - python-podman (all versions)
  - buildah (all versions)
  - podman (all versions)
  - skopeo (all versions)
  - buildah (all versions)
  - podman (all versions)
  - skopeo (all versions)
  - buildah (all versions)
  - podman (all versions)
  - python-podman (all versions)
  - rhel9/buildah (all versions)
  - rhel9/podman (all versions)
  - rhel9/skopeo (all versions)
  - skopeo (all versions)
  - buildah (all versions)
  - podman (all versions)
  - skopeo (all versions)
  - podman (all versions)
  - skopeo (all versions)
  - devspaces/udi-base-rhel10 (all versions)
  - devspaces/udi-base-rhel9 (all versions)
  - devspaces/udi-rhel9 (all versions)
  - >-
    container-native-virtualization/ocp-virt-validation-checkup-rhel9 (all
    versions)
  - quay/quay-builder-rhel8 (all versions)
  - quay/quay-builder-rhel9 (all versions)
published: '2026-09-15'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T19:17:03.080'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79699'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-79699'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2523408'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-79699.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-79699'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79699'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T18:29:49.557906Z'
epss: 0.0013
epssPercentile: 0.0297
ingestedAt: '2026-09-15T16:40:03.397Z'
---

## Overview

A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by storage/pkg/archive.UnpackLayer, ApplyLayer, or ApplyUncompressedLayer.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Low · affected: Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, … · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-79699.json)
