CERT Polska disclosed three vulnerabilities in GNU cpio affecting versions through 2.15, tracked as CVE-2026-66484, CVE-2026-66485, and CVE-2026-66486. The issues were reported by researchers from the AFINE Team and include a path traversal flaw during tar extraction, an uncontrolled memory allocation bug that can trigger stack overflow and denial of service, and an improper output escaping weakness.
The output-handling flaw can allow forged archive listings or terminal escape-sequence injection, creating opportunities to mislead users or manipulate terminal output. CERT Polska said the vulnerabilities have been addressed in specific upstream commits, while a separate security notice amplified the disclosure and directed users to the CERT advisory for details on the affected GNU cpio software.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CERT Polska disclosed three vulnerabilities affecting GNU cpio through version 2.15: a path traversal flaw in tar extraction, an uncontrolled memory allocation leading to stack overflow and denial of service, and improper output escaping that can enable forged listings or terminal escape-sequence injection.
The three GNU cpio vulnerabilities were fixed upstream in commits e2b9cbdd3354d2b1569b7390d1bc15c1930559ad, 3cd514031371d8aeeaf2048aa10103e02831aaa9, and 2ff9600c9ef32e88759843cdbde74c8db5ae9b30.
Michał Majchrowicz and Marcin Wyczechowski from the AFINE Team responsibly reported three vulnerabilities affecting GNU cpio to CERT Polska, which coordinated disclosure of the issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.