CVE-2021-38185
published 2021-08-08CVE-2021-38185: GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
4.15%
89.7th percentile
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cpio | < cpio 2.13+dfsg-5 (bookworm) | cpio 2.13+dfsg-5 (bookworm) |
| gnu | cpio | <= 2.13 | — |
| gnu | cpio | >= 0 < 2.13+dfsg-7.1~deb11u1 | 2.13+dfsg-7.1~deb11u1 |
| gnu | cpio | >= 0 < 2.13+dfsg-5 | 2.13+dfsg-5 |
| gnu | cpio | >= 0 < 2.13+dfsg-5 | 2.13+dfsg-5 |
| gnu | cpio | >= 0 < 2.13+dfsg-5 | 2.13+dfsg-5 |
| msrc | cbl2_cpio_2.13-4_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_cpio_2.13-3_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU cpio vulnerability
vendor_ubuntu·2023-08-03
CVE-2021-38185 GNU cpio vulnerability
Title: GNU cpio vulnerability
Summary: GNU cpio could be made to crash or run programs if it opened a specially
crafted file.
USN-5064-1 fixed a vulnerability in GNU. This update provides
the corresponding update for Ubuntu 14.04 LTS.
Original advisory details:
Maverick Chung and Qiaoyi Fang discovered that cpio incorrectly handled
certain pattern files. A remote attacker could use this issue to cause cpio
to crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GNU cpio vulnerability
vendor_ubuntu·2022-01-27
CVE-2021-38185 GNU cpio vulnerability
Title: GNU cpio vulnerability
Summary: GNU cpio could be made to crash or run programs if it opened a specially
crafted file.
USN-5064-1 fixed vulnerabilities in GNU cpio. This update provides
the corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
Maverick Chung and Qiaoyi Fang discovered that cpio incorrectly handled
certain pattern files. A remote attacker could use this issue to cause cpio
to crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GNU cpio vulnerability
vendor_ubuntu·2021-09-08
CVE-2021-38185 GNU cpio vulnerability
Title: GNU cpio vulnerability
Summary: GNU cpio could be made to crash or run programs if it opened a specially
crafted file.
Maverick Chung and Qiaoyi Fang discovered that cpio incorrectly handled
certain pattern files. A remote attacker could use this issue to cause cpio
to crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is un
vendor_msrc·2021-08-10·CVSS 7.8
CVE-2021-38185 [HIGH] CWE-190 GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is un
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file associated with the -E option is untrusted data.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025.
Red Hat
cpio: integer overflow in ds_fgetstr() in dstring.c can lead to an out-of-bounds write via a crafted pattern file
vendor_redhat·2021-08-06·CVSS 7.8
CVE-2021-38185 [HIGH] CWE-787 cpio: integer overflow in ds_fgetstr() in dstring.c can lead to an out-of-bounds write via a crafted pattern file
cpio: integer overflow in ds_fgetstr() in dstring.c can lead to an out-of-bounds write via a crafted pattern file
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.
A flaw was found in cpio. An integer overflow that triggers an out-of-bounds heap write can allow an attacker to execute arbitrary code via a crafted pattern file. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: cpio on Red Hat Enterprise Linux 8 is compiled with full RELRO, which mitigates
Debian
CVE-2021-38185: cpio - GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted p...
vendor_debian·2021·CVSS 7.8
CVE-2021-38185 [HIGH] CVE-2021-38185: cpio - GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted p...
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.
Scope: local
bookworm: resolved (fixed in 2.13+dfsg-5)
bullseye: resolved (fixed in 2.13+dfsg-7.1~deb11u1)
forky: resolved (fixed in 2.13+dfsg-5)
sid: resolved (fixed in 2.13+dfsg-5)
trixie: resolved (fixed in 2.13+dfsg-5)
GHSA
GHSA-pp74-ghrg-jwfh: GNU cpio through 2
ghsa_unreviewed·2022-05-24
CVE-2021-38185 [HIGH] CWE-190 GHSA-pp74-ghrg-jwfh: GNU cpio through 2
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.
OSV
CVE-2021-38185: GNU cpio through 2
osv·2021-08-08·CVSS 7.8
CVE-2021-38185 [HIGH] CVE-2021-38185: GNU cpio through 2
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=dd96882877721703e19272fe25034560b794061bhttps://github.com/fangqyi/cpiopwnhttps://lists.debian.org/debian-lts-announce/2023/06/msg00007.htmlhttps://lists.gnu.org/archive/html/bug-cpio/2021-08/msg00000.htmlhttps://lists.gnu.org/archive/html/bug-cpio/2021-08/msg00002.htmlhttps://git.savannah.gnu.org/cgit/cpio.git/commit/?id=dd96882877721703e19272fe25034560b794061bhttps://github.com/fangqyi/cpiopwnhttps://lists.debian.org/debian-lts-announce/2023/06/msg00007.htmlhttps://lists.gnu.org/archive/html/bug-cpio/2021-08/msg00000.htmlhttps://lists.gnu.org/archive/html/bug-cpio/2021-08/msg00002.html
2021-08-08
Published