An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain more privileges.
| Software | From | Fixed in |
|---|---|---|
| libarchive / libarchive | - | 3.5.2 |
| fedoraproject / fedora | 35 | 35.x |
| redhat / enterprise_linux | 8.0 | 8.0.x |
| redhat / enterprise_linux_for_power_little_endian | 8.0 | 8.0.x |
| redhat / enterprise_linux_for_ibm_z_systems | 8.0 | 8.0.x |
| redhat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.6 | 8.6.x |
| redhat / enterprise_linux_for_ibm_z_systems_eus | 8.6 | 8.6.x |
| redhat / enterprise_linux_server_aus | 8.6 | 8.6.x |
| redhat / enterprise_linux_server_tus | 8.6 | 8.6.x |
| redhat / enterprise_linux_eus | 8.6 | 8.6.x |
| redhat / enterprise_linux_for_power_little_endian_eus | 8.6 | 8.6.x |
| debian / debian_linux | 10.0 | 10.0.x |