{"apiVersion":"1.0","identifier":"CVE-2026-47699","description":"Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.0 until 0.20.0, a crafted OCI image layer can make image_rs::stream::unpack::unpack() create a hardlink outside its destination directory. In image-rs/src/stream/unpack.rs, try_hardlink_fallback() validates the hardlink source but computes the destination with destination.join(&entry_rel). Rust Path::join replaces the base when entry_rel is an absolute tar entry path, so fs::hard_link(&src_canon, &dst_entry_abs) can write attacker-controlled content to an arbitrary absolute path. In Confidential Containers the workload owner already controls trusted image content, so the issue is a workload-owner escape into the pod virtual machine rather than a crossing of the image trust boundary, but it may enable access to pod virtual machine capabilities and attestation abuse. This issue is fixed in version 0.20.0.","publishedAt":"2026-08-18T22:16:52","lastModifiedAt":"2026-08-21T20:16:35","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-47699","cvssScore":6.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","epssProbability":0.0029,"riskScore":0.66,"affectedProduct":"Confidential Containers Guest Components","affectedVersions":">=0.16.0,<0.20.0","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-47699","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-47699","en":"https://www.redsauce.net/en/cves/CVE-2026-47699","fr":"https://www.redsauce.net/fr/cves/CVE-2026-47699","pt":"https://www.redsauce.net/pt/cves/CVE-2026-47699","de":"https://www.redsauce.net/de/cves/CVE-2026-47699","sk":"https://www.redsauce.net/sk/cves/CVE-2026-47699","el":"https://www.redsauce.net/el/cves/CVE-2026-47699"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-47699"}}