CVE-2026-66484: Path Traversal in GNU cpio

Published Aug 10, 2026
·
Updated

GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar hard-link target is passed to the linktoname function without equivalent sanitization before calling link function. A tar archive provided by an attacker, containing a hard-link entry whose linkname is set to an absolute path outside the extraction directory, can cause cpio to create a hard link to an existing file outside the intended extraction directory, breaking the expected guarantee of --no-absolute-filenames and allowing archive-controlled linkage to external files.

This issue has been fixed in commit e2b9cbdd3354d2b1569b7390d1bc15c1930559ad

Affected Software

1 affected component
GNU cpio

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GNU cpio to a version that resolves this vulnerability.

    Patch e2b9cbdd3354d2b1569b7390d1bc15c1930559ad

Event History

Aug 10, 2026
CVE Published
via MITRE·10:25 AM
Data Sourced
via MITRE·10:25 AM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-66484?

CVE-2026-66484 is rated with a risk score of 43, indicating a significant vulnerability in GNU cpio.

2

What does CVE-2026-66484 affect?

CVE-2026-66484 affects the tar archive extraction functionality within GNU cpio.

3

How does the Path Traversal vulnerability in CVE-2026-66484 exploit systems?

The Path Traversal vulnerability in CVE-2026-66484 allows attackers to manipulate file paths during the extraction of tar archives, potentially leading to unauthorized file access.

4

How do I fix CVE-2026-66484?

To fix CVE-2026-66484, ensure you update to the latest version of GNU cpio that addresses this vulnerability.

5

What steps should I take to mitigate the risks associated with CVE-2026-66484?

To mitigate the risks of CVE-2026-66484, avoid using the GNU cpio tool with the --no-absolute-filenames option until the vulnerability is patched.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203