{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian10els/vex/2026/cve-2026-18508-els_os-debian10els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-20T17:31:59Z",
      "generator": {
        "date": "2026-08-20T17:31:59Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-18508-ELS_OS-DEBIAN10ELS",
      "initial_release_date": "2026-08-03T16:16:00Z",
      "revision_history": [
        {
          "date": "2026-08-03T16:16:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-20T13:31:47Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-08-20T17:31:59Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-18508"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 10",
                "product": {
                  "name": "Debian 10",
                  "product_id": "Debian-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "tar-scripts-0:1.30+dfsg-6+deb10u1.amd64",
                "product": {
                  "name": "tar-scripts-0:1.30+dfsg-6+deb10u1.amd64",
                  "product_id": "tar-scripts-0:1.30+dfsg-6+deb10u1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/tar-scripts@1.30%2Bdfsg-6%2Bdeb10u1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "tar-0:1.30+dfsg-6+deb10u1.amd64",
                "product": {
                  "name": "tar-0:1.30+dfsg-6+deb10u1.amd64",
                  "product_id": "tar-0:1.30+dfsg-6+deb10u1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/tar@1.30%2Bdfsg-6%2Bdeb10u1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "tar-scripts-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64",
                "product": {
                  "name": "tar-scripts-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64",
                  "product_id": "tar-scripts-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/tar-scripts@1.30%2Bdfsg-6%2Bdeb10u1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "tar-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64",
                "product": {
                  "name": "tar-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64",
                  "product_id": "tar-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/tar@1.30%2Bdfsg-6%2Bdeb10u1%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-scripts-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:tar-scripts-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64"
        },
        "product_reference": "tar-scripts-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:tar-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64"
        },
        "product_reference": "tar-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-scripts-0:1.30+dfsg-6+deb10u1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:tar-scripts-0:1.30+dfsg-6+deb10u1.amd64"
        },
        "product_reference": "tar-scripts-0:1.30+dfsg-6+deb10u1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-0:1.30+dfsg-6+deb10u1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:tar-0:1.30+dfsg-6+deb10u1.amd64"
        },
        "product_reference": "tar-0:1.30+dfsg-6+deb10u1.amd64",
        "relates_to_product_reference": "Debian-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-18508",
      "cwe": {
        "id": "CWE-59",
        "name": "Improper Link Resolution Before File Access ('Link Following')"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "Debian-10:tar-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64",
          "Debian-10:tar-0:1.30+dfsg-6+deb10u1.amd64",
          "Debian-10:tar-scripts-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64",
          "Debian-10:tar-scripts-0:1.30+dfsg-6+deb10u1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-18508"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:50807",
          "url": "https://access.redhat.com/errata/RHSA-2026:50807"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-18508",
          "url": "https://access.redhat.com/security/cve/CVE-2026-18508"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2509843",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509843"
        }
      ],
      "release_date": "2026-08-03T16:16:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-20T17:11:30.068502Z",
          "details": "CVE-2026-18508 is local-only and requires a user to extract a crafted archive specifically with the non-default --one-top-level option; default tar extraction is not affected, and exploitation further depends on a preexisting symlink in the extraction working directory. Even if triggered, hardlinks cannot cross filesystems and standard filesystem permissions still apply, so an unprivileged user cannot overwrite protected system files or target paths on other mounts. With these compounded preconditions and only low confidentiality/integrity impact (no availability impact), this is a low-priority issue for managed enterprise server/VM environments.",
          "product_ids": [
            "Debian-10:tar-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64",
            "Debian-10:tar-0:1.30+dfsg-6+deb10u1.amd64",
            "Debian-10:tar-scripts-0:1.30+dfsg-6+deb10u1+tuxcare.els1.amd64",
            "Debian-10:tar-scripts-0:1.30+dfsg-6+deb10u1.amd64"
          ]
        }
      ]
    }
  ]
}