Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-66484
gnu · cpio

Path Traversal in GNU cpio

Description

GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar hard-link target is passed to the link_to_name function without equivalent sanitization before calling link function. A tar archive provided by an attacker, containing a hard-link entry whose linkname is set to an absolute path outside the extraction directory, can cause cpio to create a hard link to an existing file outside the intended extraction directory, breaking the expected guarantee of --no-absolute-filenames and allowing archive-controlled linkage to external files. This issue has been fixed in commit e2b9cbdd3354d2b1569b7390d1bc15c1930559ad

Affected Products

VendorProductVersions
gnucpio0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcecpiocert_advisory90%

References

  • https://cert.pl/en/posts/2026/08/CVE-2026-66484(third-party-advisory)
  • https://git.savannah.gnu.org/cgit/cpio.git(product)

Related News (3 articles)

Tier A
Microsoft MSRC12d ago
CVE-2026-66484 Path Traversal in GNU cpio
→ No new info (linked only)
Tier B
BSI Advisories13d ago
[NEU] [niedrig] cpio: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB13d ago
CVE-2026-66484 | GNU Cpio up to 2.15 Tar Archive Extraction link_to_name path traversal
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-22
PublishedAug 10, 2026
Trending Score8
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-41992EXP
Global Buffer Overflow in GNU gzip
Trending: 54
NONECVE-2026-54371
attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr
Trending: 22
NONECVE-2026-77219
GNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image Loader
Trending: 13
NONECVE-2026-66485
Uncontrolled Memory Allocation in GNU cpio
Trending: 8
NONECVE-2026-66486
Improper Output Encoding in GNU cpio
Trending: 8

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 10, 2026
Discovered by ZDM
Aug 10, 2026