AZL-107132

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-107132.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-107132
Upstream
  • CVE-2026-89091
Published
2026-10-08T22:17:35Z
Modified
2026-10-11T14:17:49Z
Summary
CVE-2026-89091 affecting package ansible 2.17.11-1
Details

A flaw was found in ansible-core. When installing a collection with ansible-galaxy collection install, the archive extractor validates member paths using lexical path normalisation (os.path.abspath) instead of resolving symbolic links (os.path.realpath), and it performs no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink directory entries so that a subsequent file member is written outside the intended destination directory. This allows an attacker who can get a victim to install a malicious collection to overwrite arbitrary files with the privileges of the user running ansible-galaxy, leading to code execution on the control node. This is a bypass of the fix for CVE-2020-10691.

References

Affected packages

Azure Linux:3 / ansible

Package

Name
ansible
Purl
pkg:rpm/azure-linux/ansible

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.17.11-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-107132.json"