Critical Vulnerabilities in GNU cpio Affecting Multiple Ubuntu Versions

Critical Vulnerabilities in GNU cpio Affecting Multiple Ubuntu Versions

First seen 31 Aug 2026, 16:30 UTC UbuntuLinuxsecurity 57.9

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities were discovered in GNU cpio, affecting various Ubuntu LTS versions. The flaws include improper sanitization of hard-link targets (CVE-2026-66484), inadequate stack memory binding (CVE-2026-66485), and improper escaping of archive member names (CVE-2026-66486). These vulnerabilities could allow attackers to create hard links to files outside the extraction directory, cause denial of service, or inject misleading output. Users and automated systems are at risk if they are tricked into extracting specially crafted archives. The vulnerabilities were disclosed on August 10, 2026, and patches are available for affected systems. Administrators are urged to update their systems promptly to mitigate these risks.

Key Points: • Three critical vulnerabilities in GNU cpio were disclosed on August 10, 2026. • Affected systems include Ubuntu 26.04 LTS and earlier versions. • Patches are available; immediate updates are recommended to prevent exploitation.

Timeline

2026-08-10
CVE-2026-66484 published
CVE-2026-66484 details improper sanitization of hard-link targets in GNU cpio.
Ubuntu
2026-08-10
CVE-2026-66485 published
CVE-2026-66485 outlines inadequate stack memory binding during archive extraction.
Ubuntu
2026-08-10
CVE-2026-66486 published
CVE-2026-66486 describes improper escaping of archive member names in GNU cpio.
Ubuntu
2026-08-31
Security advisory published
Ubuntu released an advisory detailing the vulnerabilities and urging users to update their systems.
Linuxsecurity