Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4356 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-66485
gnu · cpio

Uncontrolled Memory Allocation in GNU cpio

Description

GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled pathname during extraction. A malicious cpio archive containing a sufficiently long nested pathname causes an unbounded stack allocation, resulting in a stack overflow and crash of the cpio process. An attacker who can supply a crafted cpio archive to a victim who extracts it can cause a denial of service. This issue has been fixed in commit 3cd514031371d8aeeaf2048aa10103e02831aaa9

Affected Products

VendorProductVersions
gnucpio0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcecpiocert_advisory90%

References

  • https://cert.pl/en/posts/2026/08/CVE-2026-66484(third-party-advisory)
  • https://git.savannah.gnu.org/cgit/cpio.git(product)

Related News (3 articles)

Tier A
Microsoft MSRC13d ago
CVE-2026-66485 Uncontrolled Memory Allocation in GNU cpio
→ No new info (linked only)
Tier B
BSI Advisories13d ago
[NEU] [niedrig] cpio: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB13d ago
CVE-2026-66485 | GNU cpio up to 2.15 src/makepath.c make_path stack-based overflow
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-789
PublishedAug 10, 2026
Trending Score8
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-41992EXP
Global Buffer Overflow in GNU gzip
Trending: 54
NONECVE-2026-54371
attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr
Trending: 22
NONECVE-2026-77219
GNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image Loader
Trending: 13
NONECVE-2026-66484
Path Traversal in GNU cpio
Trending: 8
NONECVE-2026-66486
Improper Output Encoding in GNU cpio
Trending: 8

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 10, 2026
Discovered by ZDM
Aug 10, 2026