USN-8704-1: GNU cpio vulnerabilities

Publication date

31 August 2026

Overview

Several security issues were fixed in GNU cpio.


Packages

  • cpio - a tool to manage archives of files

Details

It was discovered that cpio incorrectly sanitized hard-link targets when
extracting tar archives in copy-in mode. If a user or automated system
were tricked into extracting a specially crafted tar archive, an attacker
could possibly use this issue to create hard links to files outside the
extraction directory, even when using the --no-absolute-filenames option.
(CVE-2026-66484)

It was discovered that cpio did not properly bound the stack memory
allocated for pathnames during archive extraction. If a user or automated
system were tricked into extracting a specially crafted cpio archive, an
attacker could possibly use this issue to cause cpio to crash, resulting
in a denial of service. (CVE-2026-66485)

It was discovered that cpio did not properly escape archive member names
when listing archive contents. If a user or automated system were...

It was discovered that cpio incorrectly sanitized hard-link targets when
extracting tar archives in copy-in mode. If a user or automated system
were tricked into extracting a specially crafted tar archive, an attacker
could possibly use this issue to create hard links to files outside the
extraction directory, even when using the --no-absolute-filenames option.
(CVE-2026-66484)

It was discovered that cpio did not properly bound the stack memory
allocated for pathnames during archive extraction. If a user or automated
system were tricked into extracting a specially crafted cpio archive, an
attacker could possibly use this issue to cause cpio to crash, resulting
in a denial of service. (CVE-2026-66485)

It was discovered that cpio did not properly escape archive member names
when listing archive contents. If a user or automated system were tricked
into listing a specially crafted archive, an attacker could possibly use
this issue to inject misleading output or malicious terminal control
sequences. (CVE-2026-66486)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute cpio –  2.15+dfsg-2.1ubuntu0.1
24.04 LTS noble cpio –  2.15+dfsg-1ubuntu2.1
22.04 LTS jammy cpio –  2.13+dfsg-7ubuntu0.2
cpio-win32 –  2.13+dfsg-7ubuntu0.2
20.04 LTS focal cpio –  2.13+dfsg-2ubuntu0.4+esm1  
cpio-win32 –  2.13+dfsg-2ubuntu0.4+esm1  
18.04 LTS bionic cpio –  2.12+dfsg-6ubuntu0.18.04.4+esm1  
cpio-win32 –  2.12+dfsg-6ubuntu0.18.04.4+esm1  
16.04 LTS xenial cpio –  2.11+dfsg-5ubuntu1.1+esm2  
14.04 LTS trusty cpio –  2.11+dfsg-1ubuntu1.2+esm3  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›