PatchSiren cyber security CVE debrief
CVE-2026-79655 Red Hat CVE debrief
A flaw in the sos clean utility within the sos package allows a local attacker to create or overwrite arbitrary files by exploiting a path traversal issue during tar extraction. This is achieved by crafting a malicious tar archive, which enables the attacker to write files to arbitrary locations on the system with the privileges of the sos clean process, often running as root.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-10-06
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-10-06
Who should care
System administrators and security teams responsible for managing systems with the sos package installed should assess their exposure and take necessary actions to mitigate the vulnerability.
Why it matters
CVE-2026-79655 allows local attackers to create or overwrite arbitrary files, potentially leading to data tampering or unauthorized access, and requires verification and mitigation efforts from system administrators and security teams.
- Local attackers may create or overwrite arbitrary files with root privileges
- Potential for data tampering or unauthorized access
- Need for verifying the presence of the vulnerability and assessing exposure
- Prioritization of patching or mitigating the vulnerability
Technical summary
The sos clean utility within the sos package is vulnerable to a path traversal issue, allowing a local attacker to create or overwrite arbitrary files by crafting a malicious tar archive. This vulnerability enables the attacker to write files to arbitrary locations on the system with the privileges of the sos clean process, often running as root. The vulnerability requires verification and mitigation efforts from system administrators and security teams, especially where sos is used, and assess the exposure of local users.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their systems, especially where sos is used, and assess the exposure of local users.
Recommended defensive actions
- Verify the presence of the sos package and its version in your inventory
- Assess the exposure of local users to the sos clean process
- Consider implementing compensating controls to limit the impact of a potential exploit
- Monitor for any suspicious activity related to the sos clean process
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 7.8 and the potential for a local attacker to create or overwrite arbitrary files. The sos clean utility within the sos package is vulnerable to a path traversal issue, allowing a local attacker to create or overwrite arbitrary files by crafting a malicious tar archive. This vulnerability requires verification and mitigation efforts from system administrators and security teams. The CVE Program and NVD entries provide source-grounded details
Sources and references
Verified primary and authoritative sources
-
CVE-2026-79655 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-79655
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-79655 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79655
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-79655
-
Source reference
Unverified legacy reference
URL: https://github.com/sosreport/sos/issues/4460
-
Source reference
Unverified legacy reference
URL: https://github.com/sosreport/sos/pull/4461
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.