PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-79655 Red Hat CVE debrief

A flaw in the sos clean utility within the sos package allows a local attacker to create or overwrite arbitrary files by exploiting a path traversal issue during tar extraction. This is achieved by crafting a malicious tar archive, which enables the attacker to write files to arbitrary locations on the system with the privileges of the sos clean process, often running as root.

Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-25
Original CVE updated
2026-10-06
Advisory published
2026-08-25
Advisory updated
2026-10-06

Who should care

System administrators and security teams responsible for managing systems with the sos package installed should assess their exposure and take necessary actions to mitigate the vulnerability.

Why it matters

CVE-2026-79655 allows local attackers to create or overwrite arbitrary files, potentially leading to data tampering or unauthorized access, and requires verification and mitigation efforts from system administrators and security teams.

  • Local attackers may create or overwrite arbitrary files with root privileges
  • Potential for data tampering or unauthorized access
  • Need for verifying the presence of the vulnerability and assessing exposure
  • Prioritization of patching or mitigating the vulnerability

Technical summary

The sos clean utility within the sos package is vulnerable to a path traversal issue, allowing a local attacker to create or overwrite arbitrary files by crafting a malicious tar archive. This vulnerability enables the attacker to write files to arbitrary locations on the system with the privileges of the sos clean process, often running as root. The vulnerability requires verification and mitigation efforts from system administrators and security teams, especially where sos is used, and assess the exposure of local users.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their systems, especially where sos is used, and assess the exposure of local users.

Recommended defensive actions

  • Verify the presence of the sos package and its version in your inventory
  • Assess the exposure of local users to the sos clean process
  • Consider implementing compensating controls to limit the impact of a potential exploit
  • Monitor for any suspicious activity related to the sos clean process
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 7.8 and the potential for a local attacker to create or overwrite arbitrary files. The sos clean utility within the sos package is vulnerable to a path traversal issue, allowing a local attacker to create or overwrite arbitrary files by crafting a malicious tar archive. This vulnerability requires verification and mitigation efforts from system administrators and security teams. The CVE Program and NVD entries provide source-grounded details

Sources and references

Verified primary and authoritative sources

  • CVE-2026-79655 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-79655

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-79655 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79655

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.