Home / mailingsPDF  

[USN-8704-1] GNU cpio vulnerabilities

Posted on 31 August 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8704-1
August 31, 2026

cpio vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in GNU cpio.

Software Description:
- cpio: a tool to manage archives of files

Details:

It was discovered that cpio incorrectly sanitized hard-link targets when
extracting tar archives in copy-in mode. If a user or automated system
were tricked into extracting a specially crafted tar archive, an attacker
could possibly use this issue to create hard links to files outside the
extraction directory, even when using the --no-absolute-filenames option.
(CVE-2026-66484)

It was discovered that cpio did not properly bound the stack memory
allocated for pathnames during archive extraction. If a user or automated
system were tricked into extracting a specially crafted cpio archive, an
attacker could possibly use this issue to cause cpio to crash, resulting
in a denial of service. (CVE-2026-66485)

It was discovered that cpio did not properly escape archive member names
when listing archive contents. If a user or automated system were tricked
into listing a specially crafted archive, an attacker could possibly use
this issue to inject misleading output or malicious terminal control
sequences. (CVE-2026-66486)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
cpio 2.15+dfsg-2.1ubuntu0.1

Ubuntu 24.04 LTS
cpio 2.15+dfsg-1ubuntu2.1

Ubuntu 22.04 LTS
cpio 2.13+dfsg-7ubuntu0.2
cpio-win32 2.13+dfsg-7ubuntu0.2

Ubuntu 20.04 LTS
cpio 2.13+dfsg-2ubuntu0.4+esm1
Available with Ubuntu Pro
cpio-win32 2.13+dfsg-2ubuntu0.4+esm1
Available with Ubuntu Pro

Ubuntu 18.04 LTS
cpio 2.12+dfsg-6ubuntu0.18.04.4+esm1
Available with Ubuntu Pro
cpio-win32 2.12+dfsg-6ubuntu0.18.04.4+esm1
Available with Ubuntu Pro

Ubuntu 16.04 LTS
cpio 2.11+dfsg-5ubuntu1.1+esm2
Available with Ubuntu Pro

Ubuntu 14.04 LTS
cpio 2.11+dfsg-1ubuntu1.2+esm3
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8704-1
CVE-2026-66484, CVE-2026-66485, CVE-2026-66486

Package Information:
https://launchpad.net/ubuntu/+source/cpio/2.15+dfsg-2.1ubuntu0.1
https://launchpad.net/ubuntu/+source/cpio/2.15+dfsg-1ubuntu2.1
https://launchpad.net/ubuntu/+source/cpio/2.13+dfsg-7ubuntu0.2

--===============1877873342146325162==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP