CVE-2026-66485

EUVD-2026-55255
GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled pathname during extraction. A malicious cpio archive containing a sufficiently long nested pathname causes an unbounded stack allocation, resulting in a stack overflow and crash of the cpio process. An attacker who can supply a crafted cpio archive to a victim who extracts it can cause a denial of service.

This issue has been fixed in commit 3cd514031371d8aeeaf2048aa10103e02831aaa9
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
CERT-PLCNA
4.6 MEDIUM
LOCAL
LOW
NONE
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 7.17%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
gnucpio
𝑥
≤ 2.15
CNA
Debian logo
Debian Releases
Debian Product
Codename
cpio
bookworm
postponed
bullseye
postponed
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cpio
bionic
Fixed 2.12+dfsg-6ubuntu0.18.04.4+esm1
released
focal
Fixed 2.13+dfsg-2ubuntu0.4+esm1
released
jammy
Fixed 2.13+dfsg-7ubuntu0.2
released
noble
Fixed 2.15+dfsg-1ubuntu2.1
released
resolute
Fixed 2.15+dfsg-2.1ubuntu0.1
released
trusty
Fixed 2.11+dfsg-1ubuntu1.2+esm3
released
xenial
Fixed 2.11+dfsg-5ubuntu1.1+esm2
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
cpio
suse enterprise desktop 15 SP7
2.13-150400.3.10.1
fixed
suse enterprise sap 15 SP7
2.13-150400.3.10.1
fixed
suse enterprise server 15 SP4
2.13-150400.3.10.1
fixed
suse enterprise server 15 SP7
2.13-150400.3.10.1
fixed
cpio-lang
suse enterprise desktop 15 SP7
2.13-150400.3.10.1
fixed
suse enterprise sap 15 SP7
2.13-150400.3.10.1
fixed
suse enterprise server 15 SP4
2.13-150400.3.10.1
fixed
suse enterprise server 15 SP7
2.13-150400.3.10.1
fixed
cpio-mt
suse enterprise desktop 15 SP7
2.13-150400.3.10.1
fixed
suse enterprise sap 15 SP7
2.13-150400.3.10.1
fixed
suse enterprise server 15 SP4
2.13-150400.3.10.1
fixed
suse enterprise server 15 SP7
2.13-150400.3.10.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
cpio
Azure Linux 3.0
0:2.14-2.azl3
fixed