CVE-2021-38185: Integer Overflow
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c dsfgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/cpioto a version that resolves this vulnerability.Fixed in 2.13+dfsg-5 - Upgrade
Upgrade
ubuntu/cpioto a version that resolves this vulnerability.Fixed in 2.13+dfsg-4ubuntu4 - Upgrade
Upgrade
ubuntu/cpioto a version that resolves this vulnerability.Fixed in 2.12+dfsg-6ubuntu0.18.04.4 - Upgrade
Upgrade
ubuntu/cpioto a version that resolves this vulnerability.Fixed in 2.13+dfsg-2ubuntu0.3 - Upgrade
Upgrade
ubuntu/cpioto a version that resolves this vulnerability.Fixed in 2.13+dfsg-4ubuntu0.3 - Upgrade
Upgrade
ubuntu/cpioto a version that resolves this vulnerability.Fixed in 2.11+dfsg-5ubuntu1.1+ - Upgrade
Upgrade
ubuntu/cpioto a version that resolves this vulnerability.Fixed in 2.11+dfsg-1ubuntu1.2+ - Upgrade
Upgrade
debian/cpioto a version that resolves this vulnerability.Fixed in 2.12+dfsg-9+deb10u1Fixed in 2.13+dfsg-7.1~deb11u1Fixed in 2.13+dfsg-7.1Fixed in 2.15+dfsg-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-38185?
CVE-2021-38185 is a vulnerability in GNU cpio through 2.13 that allows attackers to execute arbitrary code via a crafted pattern file.
How severe is CVE-2021-38185?
CVE-2021-38185 has a severity score of 7.8 (high).
Which software versions are affected by CVE-2021-38185?
GNU cpio versions 2.13+dfsg-5 and earlier are affected by CVE-2021-38185.
How can I fix CVE-2021-38185?
To fix CVE-2021-38185, update GNU cpio to version 2.13+dfsg-5 or later.
Where can I find more information about CVE-2021-38185?
You can find more information about CVE-2021-38185 at the following references: - [Reference 1](https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=dd96882877721703e19272fe25034560b794061b) - [Reference 2](https://github.com/fangqyi/cpiopwn) - [Reference 3](https://lists.gnu.org/archive/html/bug-cpio/2021-08/msg00000.html)