DEBIAN-CVE-2026-103754

Source
https://security-tracker.debian.org/tracker/CVE-2026-103754
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-103754.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-103754
Upstream
  • CVE-2026-103754
Published
2026-10-01T12:17:15Z
Modified
2026-10-02T05:01:06Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L CVSS Calculator
Summary
[none]
Details

A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-runner transmit/worker protocol, re-creates symbolic links from archive content without validating the link target and applies chmod() and utime() to an unsanitized filesystem path derived from the archive member name. A crafted archive processed by a worker that consumes attacker-influenced input can create files, create symbolic links, or change permissions outside the intended target directory, which can be leveraged toward code execution.

References

Affected packages

Debian:12 / ansible-runner

Package

Name
ansible-runner
Purl
pkg:deb/debian/ansible-runner?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.3.1-2
2.3.4-1
2.3.6-1
2.4.0-0.1
2.4.1-1
2.4.2+dfsg-1
2.4.3-1
2.4.3-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-103754.json"

Debian:13 / ansible-runner

Package

Name
ansible-runner
Purl
pkg:deb/debian/ansible-runner?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.4.1-1
2.4.2+dfsg-1
2.4.3-1
2.4.3-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-103754.json"

Debian:14 / ansible-runner

Package

Name
ansible-runner
Purl
pkg:deb/debian/ansible-runner?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.4.1-1
2.4.2+dfsg-1
2.4.3-1
2.4.3-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-103754.json"