Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by storage/pkg/archive.UnpackLayer, ApplyLayer, or ApplyUncompressedLayer. | |
| Title | Podman: buildah: skopeo: containers/storage: malicious tar whiteout header allows replacement of extraction destination directory | |
| First Time appeared |
Redhat
Redhat ansible Automation Platform Redhat container Native Virtualization Redhat enterprise Linux Redhat hummingbird Redhat openshift Redhat openshift Devspaces Redhat quay |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:/a:redhat:ansible_automation_platform:2 cpe:/a:redhat:container_native_virtualization:4 cpe:/a:redhat:hummingbird:1 cpe:/a:redhat:openshift:4 cpe:/a:redhat:openshift_devspaces:3 cpe:/a:redhat:quay:3 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat ansible Automation Platform Redhat container Native Virtualization Redhat enterprise Linux Redhat hummingbird Redhat openshift Redhat openshift Devspaces Redhat quay |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-15T16:25:16.090Z
Reserved: 2026-08-25T12:24:09.488Z
Link: CVE-2026-79699
No data.
Status : Received
Published: 2026-09-15T17:17:27.083
Modified: 2026-09-15T17:17:27.083
Link: CVE-2026-79699
No data.
OpenCVE Enrichment
No data.