CVE-2026-66486
published 2026-08-10CVE-2026-66486: GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it…
PriorityP420medium4.6CVSS 4.0
AVLACLATNPRNUIAVCNVILVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.14%
3.4th percentile
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing member names with embedded newline characters or ANSI escape sequences, causing forged listing entries or terminal control sequence injection when the listing is displayed.
This issue has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | cpio | <= 2.15 | — |
| gnu | cpio | — | — |
| ubuntu | cpio | — | — |
CVSS provenance
nvdv4.04.6MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU cpio vulnerabilities
vendor_ubuntu·2026-08-31·CVSS 4.6
CVE-2026-66485 [MEDIUM] GNU cpio vulnerabilities
Title: GNU cpio vulnerabilities
Summary: Several security issues were fixed in GNU cpio.
It was discovered that cpio incorrectly sanitized hard-link targets when
extracting tar archives in copy-in mode. If a user or automated system
were tricked into extracting a specially crafted tar archive, an attacker
could possibly use this issue to create hard links to files outside the
extraction directory, even when using the --no-absolute-filenames option.
(CVE-2026-66484)
It was discovered that cpio did not properly bound the stack memory
allocated for pathnames during archive extraction. If a user or automated
system were tricked into extracting a specially crafted cpio archive, an
attacker could possibly use this issue to cause cpio to crash, resulting
in a denial of service. (CVE-2026-66485
Red Hat
cpio: GNU cpio: Terminal control sequence injection via crafted archive member names
vendor_redhat·2026-08-10·CVSS 4.6
CVE-2026-66486 [MEDIUM] CWE-94 cpio: GNU cpio: Terminal control sequence injection via crafted archive member names
cpio: GNU cpio: Terminal control sequence injection via crafted archive member names
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing member names with embedded newline characters or ANSI escape sequences, causing forged listing entries or terminal control sequence injection when the listing is displayed.
This issue has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30
A flaw was found in GNU cpio. This vulnerability occurs in the archive member listing functionality, where member names are printed directly without proper encoding or escaping. A remote a
GHSA
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality.
ghsa_unreviewed·2026-08-10
CVE-2026-66486 [MEDIUM] CWE-116 GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality.
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing member names with embedded newline characters or ANSI escape sequences, causing forged listing entries or terminal control sequence injection when the listing is displayed.
This issue has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30
No detection rules found.
No public exploits indexed.
2026-08-10
Published