Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-39243

CVE-2026-39243: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium6.1

    Medium [CVE-2026-39243] File disclosure and corruption via arbitrary hardlink creation

    CVE-2026-39243Source published Source updated

    decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === 'link'), the x.linkname field from the archive is passed directly to fs.link() without validation (index.js line 113). An attacker can craft an archive with a hardlink entry whose linkname is an absolute path to any file on the same filesystem. This creates a hardlink inside the extraction directory that shares the same inode as the target file, enabling both reading and overwriting the original file's content. Hardlinks are limited to files on the same filesystem and cannot target directories. A flaw was found in decompress. An attacker can craft a malicious archive that, when extracted, allows for arbitrary…

    Affected products in this advisory
    • Red Hat Hardened Images
    • Red Hat Advanced Cluster Management for Kubernetes 2
    • Red Hat Build of Keycloak
    Source-reported affected versions
    • < 4.2.2
    Source-reported fixed versions
    • dotnet8-0-main-8.0.128-1.1.hum1
    • RHSA-2026:37577
    Mitigation guidance
    • To mitigate this issue, avoid extracting archives from untrusted or unknown sources. When processing archives from potentially untrusted origins, consider using a sandboxed environment to limit the impact of any malicious content.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery