CVE-2026-39243
CVE-2026-39243: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityMedium6.1
Medium [CVE-2026-39243] File disclosure and corruption via arbitrary hardlink creation
CVE-2026-39243Source published Source updated
decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === 'link'), the x.linkname field from the archive is passed directly to fs.link() without validation (index.js line 113). An attacker can craft an archive with a hardlink entry whose linkname is an absolute path to any file on the same filesystem. This creates a hardlink inside the extraction directory that shares the same inode as the target file, enabling both reading and overwriting the original file's content. Hardlinks are limited to files on the same filesystem and cannot target directories. A flaw was found in decompress. An attacker can craft a malicious archive that, when extracted, allows for arbitrary…
- Affected products in this advisory
- Red Hat Hardened Images
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Build of Keycloak
- Source-reported affected versions
- < 4.2.2
- Source-reported fixed versions
- dotnet8-0-main-8.0.128-1.1.hum1
- RHSA-2026:37577
- Mitigation guidance
- To mitigate this issue, avoid extracting archives from untrusted or unknown sources. When processing archives from potentially untrusted origins, consider using a sandboxed environment to limit the impact of any malicious content.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.