Skip to content
Ubuntu 26.04 LTS GNU cpio Important Input Sanitization Flaws USN-8704

Ubuntu 26.04 LTS GNU cpio Important Input Sanitization Flaws USN-8704

Linuxsecurity •LinuxSecurity Advisories • August 31, 2026

Find practical guidance for preventing, investigating, and responding to Linux security problems. Find practical guidance for preventing, investigating, and responding to Linux security problems. _ Review Linux Privileges ×

Several security issues were fixed in GNU cpio. Software Description: - cpio: a tool to manage archives of files Details: It was discovered that cpio incorrectly sanitized hard-link targets when extracting tar archives in copy-in mode. If a user or automated system were tricked into extracting a specially crafted tar archive, an attacker could possibly use this issue to create hard links to files outside the extraction directory, even when using the --no-absolute-filenames option. (CVE-2026-66484) It was discovered that cpio did not properly bound the stack memory allocated for pathnames during archive extraction. If a user or automated system were tricked into extracting a specially crafted cpio archive, an attacker could possibly use this issue to cause cpio to crash, resulting in a denial of service. (CVE-2026-66485) It was discovered that cpio did not properly escape archive member names when listing archive contents. If a user or automated system were tricked into listing... Read the Full Advisory

Several security issues were fixed in GNU cpio.

Software Description:

- cpio: a tool to manage archives of files

It was discovered that cpio incorrectly sanitized hard-link targets when

extracting tar archives in copy-in mode. If a user or automated system

were tricked into extracting a specially crafted tar archive, an attacker

could possibly use this issue to create hard links to files outside the

extraction directory, even when using the --no-absolute-filenames option.

It was discovered that cpio did not properly bound the stack memory

allocated for pathnames during archive extraction. If a user or automated

system were tricked into extracting a specially crafted cpio archive, an

attacker could possibly use this issue to cause cpio to crash, resulting

in a denial of service. (CVE-2026-66485)

It was discovered that cpio did not properly escape archive member names

when listing archive contents. If a user or automated system were tricked

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS cpio 2.15+dfsg-2.1ubuntu0.1 Ubuntu 24.04 LTS cpio 2.15+dfsg-1ubuntu2.1 Ubuntu 22.04 LTS cpio 2.13+dfsg-7ubuntu0.2 cpio-win32 2.13+dfsg-7ubuntu0.2 Ubuntu 20.04 LTS cpio 2.13+dfsg-2ubuntu0.4+esm1 Available with Ubuntu Pro cpio-win32 2.13+dfsg-2ubuntu0.4+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS cpio 2.12+dfsg-6ubuntu0.18.04.4+esm1 Available with Ubuntu Pro cpio-win32 2.12+dfsg-6ubuntu0.18.04.4+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS cpio 2.11+dfsg-5ubuntu1.1+esm2 Available with Ubuntu Pro Ubuntu 14.04 LTS cpio 2.11+dfsg-1ubuntu1.2+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

CVE-2026-66484, CVE-2026-66485, CVE-2026-66486

Ubuntu Security Notice USN-8704-1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases