A vulnerability was discovered in the sos clean utility, part of the sos package used for system diagnostics. The flaw allows a local attacker to perform arbitrary file creation or overwrite by crafting a malicious tar archive. The vulnerability stems from improper validation of symlink and hardlink targets during tar extraction, enabling path traversal attacks. Since the sos clean process frequently runs with root privileges, a successful exploit can write files to any location on the system. This poses a significant privilege escalation and system integrity risk. The issue has been tracked and reported via Red Hat's Bugzilla and the upstream GitHub repository. Fixes are being addressed through a pull request in the sosreport/sos GitHub project. The vulnerability affects Linux systems running the sos package, particularly Red Hat-based distributions.