{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu16.04els/vex/2026/cve-2026-18508-els_os-ubuntu16_04els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-26T16:43:32Z",
      "generator": {
        "date": "2026-08-26T16:43:32Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-18508-ELS_OS-UBUNTU16.04ELS",
      "initial_release_date": "2026-08-03T16:16:00Z",
      "revision_history": [
        {
          "date": "2026-08-03T16:16:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-26T12:56:24Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-08-26T16:43:32Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-18508"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 16.04",
                "product": {
                  "name": "Ubuntu 16.04",
                  "product_id": "Ubuntu-16",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "tar-scripts-0:1.28-2.1ubuntu0.2.amd64",
                "product": {
                  "name": "tar-scripts-0:1.28-2.1ubuntu0.2.amd64",
                  "product_id": "tar-scripts-0:1.28-2.1ubuntu0.2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/tar-scripts@1.28-2.1ubuntu0.2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "tar-0:1.28-2.1ubuntu0.2.amd64",
                "product": {
                  "name": "tar-0:1.28-2.1ubuntu0.2.amd64",
                  "product_id": "tar-0:1.28-2.1ubuntu0.2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/tar@1.28-2.1ubuntu0.2?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
                "product": {
                  "name": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
                  "product_id": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/tar-scripts@1.28-2.1ubuntu0.2%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
                "product": {
                  "name": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
                  "product_id": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/tar-scripts@1.28-2.1ubuntu0.2%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
                "product": {
                  "name": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
                  "product_id": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/tar@1.28-2.1ubuntu0.2%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
                "product": {
                  "name": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
                  "product_id": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/tar@1.28-2.1ubuntu0.2%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64"
        },
        "product_reference": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64"
        },
        "product_reference": "tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64"
        },
        "product_reference": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64"
        },
        "product_reference": "tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-scripts-0:1.28-2.1ubuntu0.2.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2.amd64"
        },
        "product_reference": "tar-scripts-0:1.28-2.1ubuntu0.2.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "tar-0:1.28-2.1ubuntu0.2.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2.amd64"
        },
        "product_reference": "tar-0:1.28-2.1ubuntu0.2.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-18508",
      "cwe": {
        "id": "CWE-59",
        "name": "Improper Link Resolution Before File Access ('Link Following')"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
          "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
          "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2.amd64",
          "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
          "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
          "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-18508"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:50807",
          "url": "https://access.redhat.com/errata/RHSA-2026:50807"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-18508",
          "url": "https://access.redhat.com/security/cve/CVE-2026-18508"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2509843",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2509843"
        }
      ],
      "release_date": "2026-08-03T16:16:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-26T14:17:28.204161Z",
          "details": "Deprioritize: exploitation is local and requires user interaction with a crafted archive plus two non-default conditions—tar must be invoked with --one-top-level and a specific symlink must already exist under the extraction working directory; extracting into a new/empty directory is unaffected. The flaw confers no privilege escalation and any write occurs via hardlinks resolved from the working directory, which are limited to the same filesystem and to paths the extracting user can reach, yielding only limited confidentiality/integrity impact. In centrally managed VM/server contexts where archives are typically handled in controlled workflows, these preconditions make practical exploitation unlikely.",
          "product_ids": [
            "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
            "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
            "Ubuntu-16:tar-0:1.28-2.1ubuntu0.2.amd64",
            "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els1.amd64",
            "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2+tuxcare.els2.amd64",
            "Ubuntu-16:tar-scripts-0:1.28-2.1ubuntu0.2.amd64"
          ]
        }
      ]
    }
  ]
}