CVE-2018-20835: Tar-Fs Project Tar-Fs

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content.

Affected products

Published 2019-04-30. Last modified 2026-06-17.