Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-66484— Path Traversal in GNU cpio

Quick assessment

Affected
GNU cpio
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GNU cpio是美国GNU基金会开源的一款文件归档与提取工具。 GNU cpio 2.15及之前版本存在路径遍历漏洞,该漏洞源于提取tar归档时,使用--no-absolute-filenames选项处理硬链接目标路径时未进行充分清理,可能允许攻击者创建指向提取目录外部文件的硬链接。

CVSS 4.6 · Medium EPSS 0.20% · P8

Possible ATT&CK Techniques 1 AI

T1564.004 · NTFS File Attributes

Affected Version Matrix 1

VendorProduct Version RangeStatus
GNU cpio ≤ 2.15 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-66484

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Path Traversal in GNU cpio
Source: CVE Program / CVE List V5
Vulnerability Description
GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar hard-link target is passed to the link_to_name function without equivalent sanitization before calling link function. A tar archive provided by an attacker, containing a hard-link entry whose linkname is set to an absolute path outside the extraction directory, can cause cpio to create a hard link to an existing file outside the intended extraction directory, breaking the expected guarantee of --no-absolute-filenames and allowing archive-controlled linkage to external files. This issue has been fixed in commit e2b9cbdd3354d2b1569b7390d1bc15c1930559ad
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5
Vulnerability Title
GNU cpio 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GNU cpio是美国GNU基金会开源的一款文件归档与提取工具。 GNU cpio 2.15及之前版本存在路径遍历漏洞,该漏洞源于提取tar归档时,使用--no-absolute-filenames选项处理硬链接目标路径时未进行充分清理,可能允许攻击者创建指向提取目录外部文件的硬链接。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
GNU cpio 0 ~ 2.15 -

II. Public POCs for CVE-2026-66484

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-66484

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-66484 (1)

Security Blog Posts for CVE-2026-66484 (1)

Same Patch Batch · GNU · 2026-08-10 · 7 CVEs total

CVE-2026-71392 5.3 MEDIUM Integer Overflow in GNU Emacs for Android
CVE-2026-71393 5.3 MEDIUM Heap Buffer Overflow in GNU Emacs for Android
CVE-2026-71391 5.3 MEDIUM Off-by-One Error in GNU Emacs for Android
CVE-2026-71394 5.3 MEDIUM Heap Use of Uninitialized Memory in GNU Emacs for Android
CVE-2026-66486 4.6 MEDIUM Improper Output Encoding in GNU cpio
CVE-2026-66485 4.6 MEDIUM Uncontrolled Memory Allocation in GNU cpio

IV. Related Vulnerabilities

V. Comments for CVE-2026-66484

No comments yet


Leave a comment