Packages
- cpio - a tool to manage archives of files
Details
It was discovered that cpio incorrectly sanitized hard-link targets when
extracting tar archives in copy-in mode. If a user or automated system
were tricked into extracting a specially crafted tar archive, an attacker
could possibly use this issue to create hard links to files outside the
extraction directory, even when using the --no-absolute-filenames option.
(CVE-2026-66484)
It was discovered that cpio did not properly bound the stack memory
allocated for pathnames during archive extraction. If a user or automated
system were tricked into extracting a specially crafted cpio archive, an
attacker could possibly use this issue to cause cpio to crash, resulting
in a denial of service. (CVE-2026-66485)
It was discovered that cpio did not properly escape archive member names
when listing archive contents. If a user or automated system were...
It was discovered that cpio incorrectly sanitized hard-link targets when
extracting tar archives in copy-in mode. If a user or automated system
were tricked into extracting a specially crafted tar archive, an attacker
could possibly use this issue to create hard links to files outside the
extraction directory, even when using the --no-absolute-filenames option.
(CVE-2026-66484)
It was discovered that cpio did not properly bound the stack memory
allocated for pathnames during archive extraction. If a user or automated
system were tricked into extracting a specially crafted cpio archive, an
attacker could possibly use this issue to cause cpio to crash, resulting
in a denial of service. (CVE-2026-66485)
It was discovered that cpio did not properly escape archive member names
when listing archive contents. If a user or automated system were tricked
into listing a specially crafted archive, an attacker could possibly use
this issue to inject misleading output or malicious terminal control
sequences. (CVE-2026-66486)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
| 26.04 LTS resolute | cpio – 2.15+dfsg-2.1ubuntu0.1 | ||
| 24.04 LTS noble | cpio – 2.15+dfsg-1ubuntu2.1 | ||
| 22.04 LTS jammy | cpio – 2.13+dfsg-7ubuntu0.2 | ||
| cpio-win32 – 2.13+dfsg-7ubuntu0.2 | |||
| 20.04 LTS focal | cpio – 2.13+dfsg-2ubuntu0.4+esm1 | ||
| cpio-win32 – 2.13+dfsg-2ubuntu0.4+esm1 | |||
| 18.04 LTS bionic | cpio – 2.12+dfsg-6ubuntu0.18.04.4+esm1 | ||
| cpio-win32 – 2.12+dfsg-6ubuntu0.18.04.4+esm1 | |||
| 16.04 LTS xenial | cpio – 2.11+dfsg-5ubuntu1.1+esm2 | ||
| 14.04 LTS trusty | cpio – 2.11+dfsg-1ubuntu1.2+esm3 | ||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.