CVE-2026-79705: Red Hat Ansible Automation Platform 2

Medium severity, CVSS 4.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Buildah itself uses chroot hardening and is not affected.

Affected products

  • Red Hat Red Hat Ansible Automation Platform 2
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Hardened Images: before 6.1.3-1.hum1 (fixed in 6.1.3-1.hum1)
  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Openshift Dev Spaces
  • Red Hat Red Hat Openshift Virtualization 4
  • Red Hat Red Hat Quay 3

Published 2026-09-15. Last modified 2026-10-02.