Back to vendor advisories
Microsoft Security Response CenterCVE-2026-105712

gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.

LowVendor CVSS 3.6 / 10 1 CVE Published Oct 7, 2026 at 1:02 AM UTC

Summary

Mariner

Products covered

  • azl3 gnupg2 2.4.9-3 on Azure Linux 3.0

Remediation

Release Notes

CVEs in this advisory 1

Updates

  1. Published by Microsoft Security Response Center

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.