AZL-103254

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103254.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-103254
Upstream
Published
2026-09-15T20:19:19Z
Modified
2026-09-22T05:34:53Z
Summary
CVE-2026-88922 affecting package packer 1.9.5-20
Details

The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bits. Where extraction is performed by a privileged user, this may allow a local actor to obtain the privileges of the extracting process. This vulnerability (CVE-2026-88922) is fixed in go-getter 1.8.9 and 2.2.4.

References

Affected packages

Azure Linux:3 / packer

Package

Name
packer
Purl
pkg:rpm/azure-linux/packer

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.9.5-20

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103254.json"