CVE-2026-105712

low

Description

gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.

References

https://static.dev.gnupg.org/T8159.html

https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html

https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-92634

Details

Source: Mitre, NVD

Published: 2026-10-05

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 2.6

Vector: CVSS2#AV:L/AC:H/Au:N/C:N/I:P/A:P

Severity: Low

CVSS v3

Base Score: 3.6

Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L

Severity: Low

EPSS

EPSS: 0.00123