CERT Polska disclosed three vulnerabilities in GNU cpio affecting versions through 2.15, tracked as CVE-2026-66484, CVE-2026-66485, and CVE-2026-66486. The issues were reported by researchers from the AFINE Team and fixed in upstream commits. The most serious flaw allows path traversal during archive extraction, a weakness aligned with CWE-22, in which crafted file paths can escape the intended extraction directory and potentially overwrite or access files outside the restricted path.
The additional bugs include an uncontrolled memory allocation issue mapped to CWE-789 that can trigger a stack overflow and denial of service, and an improper output escaping flaw that can produce forged archive listings or inject terminal escape sequences. Together, the vulnerabilities expose users handling untrusted archives to file-system compromise, service disruption, and deceptive terminal output, underscoring the risk of insufficient pathname validation, unsafe memory handling, and unescaped archive metadata in command-line archive tools.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-10, CERT Polska published CVE-2026-66484, CVE-2026-66485, and CVE-2026-66486 affecting GNU cpio through version 2.15. The disclosures covered a path traversal flaw, an uncontrolled memory allocation leading to stack overflow and denial of service, and an output escaping issue affecting archive listings.
GNU cpio fixed CVE-2026-66486, a CWE-116 issue in archive member listing where names were printed without quoting or escaping, enabling forged listings or terminal escape-sequence injection. The fix was made in upstream commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30.
GNU cpio fixed CVE-2026-66485, a CWE-789 issue in src/makepath.c where archive-controlled path lengths could drive unbounded alloca-based stack allocation and crash the process during extraction. The fix was made in upstream commit 3cd514031371d8aeeaf2048aa10103e02831aaa9.
GNU cpio fixed CVE-2026-66484, a CWE-22 path traversal issue in tar extraction copy-in mode where an unsanitized hard-link target could create a hard link to an external absolute path despite --no-absolute-filenames. The fix was made in upstream commit e2b9cbdd3354d2b1569b7390d1bc15c1930559ad.
CERT Polska received and coordinated disclosure for three GNU cpio vulnerabilities reported by Michał Majchrowicz and Marcin Wyczechowski from the AFINE Team. The source does not provide a specific date for when the report was submitted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cert.pl
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.