GNU cpio是美国GNU基金会开源的一款文件归档与提取工具。 GNU cpio 2.15及之前版本存在路径遍历漏洞,该漏洞源于提取tar归档时,使用--no-absolute-filenames选项处理硬链接目标路径时未进行充分清理,可能允许攻击者创建指向提取目录外部文件的硬链接。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71392 | 5.3 MEDIUM | Integer Overflow in GNU Emacs for Android |
| CVE-2026-71393 | 5.3 MEDIUM | Heap Buffer Overflow in GNU Emacs for Android |
| CVE-2026-71391 | 5.3 MEDIUM | Off-by-One Error in GNU Emacs for Android |
| CVE-2026-71394 | 5.3 MEDIUM | Heap Use of Uninitialized Memory in GNU Emacs for Android |
| CVE-2026-66486 | 4.6 MEDIUM | Improper Output Encoding in GNU cpio |
| CVE-2026-66485 | 4.6 MEDIUM | Uncontrolled Memory Allocation in GNU cpio |
No comments yet