|
|
Log in / Subscribe / Register

Ubuntu alert USN-8704-1 (cpio)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8704-1] GNU cpio vulnerabilities
Date:  Mon, 31 Aug 2026 15:41:59 +0000
Message-ID:  <E1x1491-0006dN-Nf@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8704-1 August 31, 2026 cpio vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in GNU cpio. Software Description: - cpio: a tool to manage archives of files Details: It was discovered that cpio incorrectly sanitized hard-link targets when extracting tar archives in copy-in mode. If a user or automated system were tricked into extracting a specially crafted tar archive, an attacker could possibly use this issue to create hard links to files outside the extraction directory, even when using the --no-absolute-filenames option. (CVE-2026-66484) It was discovered that cpio did not properly bound the stack memory allocated for pathnames during archive extraction. If a user or automated system were tricked into extracting a specially crafted cpio archive, an attacker could possibly use this issue to cause cpio to crash, resulting in a denial of service. (CVE-2026-66485) It was discovered that cpio did not properly escape archive member names when listing archive contents. If a user or automated system were tricked into listing a specially crafted archive, an attacker could possibly use this issue to inject misleading output or malicious terminal control sequences. (CVE-2026-66486) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS cpio 2.15+dfsg-2.1ubuntu0.1 Ubuntu 24.04 LTS cpio 2.15+dfsg-1ubuntu2.1 Ubuntu 22.04 LTS cpio 2.13+dfsg-7ubuntu0.2 cpio-win32 2.13+dfsg-7ubuntu0.2 Ubuntu 20.04 LTS cpio 2.13+dfsg-2ubuntu0.4+esm1 Available with Ubuntu Pro cpio-win32 2.13+dfsg-2ubuntu0.4+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS cpio 2.12+dfsg-6ubuntu0.18.04.4+esm1 Available with Ubuntu Pro cpio-win32 2.12+dfsg-6ubuntu0.18.04.4+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS cpio 2.11+dfsg-5ubuntu1.1+esm2 Available with Ubuntu Pro Ubuntu 14.04 LTS cpio 2.11+dfsg-1ubuntu1.2+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8704-1 CVE-2026-66484, CVE-2026-66485, CVE-2026-66486 Package Information: https://launchpad.net/ubuntu/+source/cpio/2.15+dfsg-2.1ub... https://launchpad.net/ubuntu/+source/cpio/2.15+dfsg-1ubun... https://launchpad.net/ubuntu/+source/cpio/2.13+dfsg-7ubun...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmqVoD8ACgkQcpJm3tlz hgHnFg//ZWQq0nQ72a1XN2mVn4u4WHTmn72Ap29ReKvgYzHPELgmKbpDruczCqP2 pp7Wwf29TOgoMkhbdlgFhIheiolAMSesIsrbr/+SnMxdtenDdmLu6+c2mnTq7ADb GLKjfb3IV+2qwacA2K/pApsWpkgXJ9BIaNdzOKBnhmzPEu66gUklG55vVJPqPwb1 40A+zPNFRD0YFlRpRG/zYniLaOK9HiwoOe5kg1X5++fB5N0DlvpP7rrpDJ0Nurn5 8j7vfyiwUDwp1fqRNILkxLYZ3Uo8sOkr25AYXjpq92g0hx73Cg6owGkdq8rc744X r9hdZIjvWJewX7k6mYyWsqxcLnzfTsbPUFe6sUPMNsNZpP6z+luubrTTGBx7vpFO 6GhPUxhas66suRoPksmM+vER1wJosQFTJQDGNWOm6cD3YcrDcZVj4kLpvlfH9KHj RfN9c8Z36S68GK3265zMSUdbXTp7xD7w/uqjmO2mUA6nsuq2Q9cc7APOexZoyX63 EzU8P+s9Rqs1ELRYywBkHZqRoQos0ANcCGstz9eH0KCjeUiBpSKhrGxZmJwx2AwI OLv6H8WP+RTkLb/LTYZpdyQHgzItT8zdaFi0yxnMQHCcaiOpMRb2JUuWcJR8Jywf 9HQQeLDogjlWgAOAx7b9BnAJKCeqYE7aPRPSbeNqjZ7huDMt8pM= =yI5z -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds