Why You Should Never Run unrar as Root on Linux

Running the unrar utility as the root user on Linux poses critical security risks, including arbitrary file overwrites, privilege escalation, and unintended file ownership changes. This article explains the technical consequences of executing unrar with administrative privileges, details the dangers of archive-based exploits like path traversal, and explains how to safely extract RAR archives on a Linux system.

Arbitrary File Overwrite via Path Traversal

When unrar processes an archive, it unpacks files according to the paths stored within the archive headers. Attackers can craft malicious RAR archives containing path traversal sequences (such as ../../etc/cron.d/malicious_job).

When executed by an unprivileged user, the operating system blocks writes to protected system directories. However, when run as root, unrar possesses full write permissions across the entire filesystem. A malicious archive can silently overwrite critical system binaries, configuration files (such as /etc/shadow), or scheduled tasks, resulting in immediate and complete system compromise. A notable real-world example is CVE-2022-30333, a path traversal vulnerability in unRAR that allowed attackers to write arbitrary files anywhere on the disk if the process had root privileges.

Memory Corruption and Remote Code Execution

The unRAR codebase is primarily written in C++, a memory-unsafe language. Complex file formats like RAR require intricate parsing logic for compression algorithms, header metadata, and encryption layers. Over the years, multiple memory corruption vulnerabilities—such as buffer overflows and out-of-bounds writes—have been discovered in various versions of unrar.

If a vulnerability exists in the parsing engine, an attacker can craft an archive that triggers a buffer overflow when parsed. If you execute this command as root, any shellcode or payload triggered by that exploit immediately inherits root privileges, giving an attacker persistent superuser access to the host machine.

RAR archives can store symbolic and hard links. If unrar does not strictly validate where these links point, extracting an archive as root can allow an attacker to create links targeting sensitive system locations. Subsequent file operations might then write data into files like /etc/passwd or /root/.bashrc, bypassing standard Linux access control policies.

File Ownership and Permission Issues

Any file or directory extracted by the root user will be owned by root:root by default. If you extract an archive intended for a specific application (such as a web server running under www-data or a database running under mysql), the service will often fail to read, write, or execute those files due to permission denied errors. This frequently leads administrators into fixing permissions using dangerous commands like chmod 777.

Archive Bombs and Disk Exhaustion

An archive bomb (or decompression bomb) is a tiny file that expands to hundreds of gigabytes or terabytes of data once extracted. Normal user accounts can be constrained by disk quotas (edquota) or standard storage limits. Running unrar as root circumvents safety thresholds, allowing a malicious or corrupted archive to fill the root partition (/) entirely. When the root partition runs out of space, critical system services, logging facilities, and system daemons will crash, causing a complete system denial of service.

Safe Practices for Extracting RAR Archives

To eliminate these risks, adhere to the following best practices:

  • Always Run as an Unprivileged User: Never use sudo unrar or extract archives while logged into the root account. Run the extraction utility under a standard, non-privileged user account.
  • Use Sandboxing or Isolation: If you must extract untrusted archives, do so inside an ephemeral Docker container or an isolated virtual machine without access to host volumes.
  • Keep unrar Updated: Ensure the package is updated through your distribution’s package manager to protect against known security vulnerabilities.