CVE-2026-79705: Red Hat Ansible Automation Platform 2
Medium severity, CVSS 4.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Buildah itself uses chroot hardening and is not affected.
Affected products
- Red Hat Red Hat Ansible Automation Platform 2
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Hardened Images: before 6.1.3-1.hum1 (fixed in 6.1.3-1.hum1)
- Red Hat Red Hat Openshift Container Platform 4
- Red Hat Red Hat Openshift Dev Spaces
- Red Hat Red Hat Openshift Virtualization 4
- Red Hat Red Hat Quay 3
Published 2026-09-15. Last modified 2026-10-02.