CVE-2026-66484

EUVD-2026-55256
GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar hard-link target is passed to the link_to_name function without equivalent sanitization before calling link function. A tar archive provided by an attacker, containing a hard-link entry whose linkname is set to an absolute path outside the extraction directory, can cause cpio to create a hard link to an existing file outside the intended extraction directory, breaking the expected guarantee of --no-absolute-filenames and allowing archive-controlled linkage to external files.

This issue has been fixed in commit e2b9cbdd3354d2b1569b7390d1bc15c1930559ad
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
CERT-PLCNA
4.6 MEDIUM
LOCAL
LOW
NONE
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 8.33%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
gnucpio
𝑥
≤ 2.15
CNA
Debian logo
Debian Releases
Debian Product
Codename
cpio
bookworm
postponed
bullseye
postponed
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cpio
bionic
Fixed 2.12+dfsg-6ubuntu0.18.04.4+esm1
released
focal
Fixed 2.13+dfsg-2ubuntu0.4+esm1
released
jammy
Fixed 2.13+dfsg-7ubuntu0.2
released
noble
Fixed 2.15+dfsg-1ubuntu2.1
released
resolute
Fixed 2.15+dfsg-2.1ubuntu0.1
released
trusty
Fixed 2.11+dfsg-1ubuntu1.2+esm3
released
xenial
Fixed 2.11+dfsg-5ubuntu1.1+esm2
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
cpio
suse enterprise desktop 15 SP7
2.13-150400.3.10.1
fixed
suse enterprise sap 15 SP7
2.13-150400.3.10.1
fixed
suse enterprise server 15 SP4
2.13-150400.3.10.1
fixed
suse enterprise server 15 SP7
2.13-150400.3.10.1
fixed
cpio-lang
suse enterprise desktop 15 SP7
2.13-150400.3.10.1
fixed
suse enterprise sap 15 SP7
2.13-150400.3.10.1
fixed
suse enterprise server 15 SP4
2.13-150400.3.10.1
fixed
suse enterprise server 15 SP7
2.13-150400.3.10.1
fixed
cpio-mt
suse enterprise desktop 15 SP7
2.13-150400.3.10.1
fixed
suse enterprise sap 15 SP7
2.13-150400.3.10.1
fixed
suse enterprise server 15 SP4
2.13-150400.3.10.1
fixed
suse enterprise server 15 SP7
2.13-150400.3.10.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
cpio
Azure Linux 3.0
0:2.14-2.azl3
fixed