AZL-105962

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105962.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105962
Upstream
Published
2026-10-05T19:17:19Z
Modified
2026-10-07T05:34:51Z
Summary
CVE-2026-105712 affecting package gnupg2 2.4.9-3
Details

gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.

References

Affected packages

Azure Linux:3 / gnupg2

Package

Name
gnupg2
Purl
pkg:rpm/azure-linux/gnupg2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.4.9-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105962.json"