gpgtar can write outside the selected extraction directory through a pre-existing symlink
Fixed in: GnuPG 2.5.19
patched
details
Finding IDs
F-GNUPG-001-002
CVE
CVE-2026-105712
Status
patched
Fixed in
GnuPG 2.5.19
Note
The published CVE applies to gpgtar before 2.5.19 when extraction with --directory targets an existing directory containing a pre-existing symlink. A fresh empty extraction directory does not have this risk; writes remain limited by the extraction user permissions. The existing F-GNUPG-001-002 record documents the public fix and GnuPG T8159 reporter acknowledgement.
Security area (1seal assessment): Authorization. A pre-existing symlink can redirect extracted output outside the selected directory. Reviewed 6 Oct 2026.
tool:gpgtar: Check the output directory with --directory.
fixed publicly
details
Finding IDs
F-GNUPG-001-002
Status
fixed publicly
Reported via
private reporting channel
Note
public GnuPG T8159 tracks gpgtar write outside --directory via symlink traversal with Reported-by: Oleh Konko; commit 7a2692fe5e58 landed on 2026-03-24 and GnuPG 2.5.19 announced the fix for gpgtar -C/--directory output-directory checking on 2026-04-24. CVE-2026-105712 was published on 2026-10-05 for this gpgtar issue.
Security area (1seal assessment): Authorization. gpgtar checks that the requested extraction directory is empty and not a symlink before writing plaintext files. Reviewed 21 Sep 2026.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.