GNU cpio是美国GNU基金会开源的一款文件归档与提取工具。 GNU cpio 2.15及之前版本存在资源管理错误漏洞,该漏洞源于src/makepath.c文件的make_path函数中不受控制的内存分配,使用alloca基于argpath长度分配栈内存,恶意cpio存档中包含超长嵌套路径名可导致未绑定的栈分配,造成栈溢出和崩溃,从而导致拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71392 | 5.3 MEDIUM | Integer Overflow in GNU Emacs for Android |
| CVE-2026-71393 | 5.3 MEDIUM | Heap Buffer Overflow in GNU Emacs for Android |
| CVE-2026-71391 | 5.3 MEDIUM | Off-by-One Error in GNU Emacs for Android |
| CVE-2026-71394 | 5.3 MEDIUM | Heap Use of Uninitialized Memory in GNU Emacs for Android |
| CVE-2026-66484 | 4.6 MEDIUM | Path Traversal in GNU cpio |
| CVE-2026-66486 | 4.6 MEDIUM | Improper Output Encoding in GNU cpio |
No comments yet