Description
GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar hard-link target is passed to the link_to_name function without equivalent sanitization before calling link function. A tar archive provided by an attacker, containing a hard-link entry whose linkname is set to an absolute path outside the extraction directory, can cause cpio to create a hard link to an existing file outside the intended extraction directory, breaking the expected guarantee of --no-absolute-filenames and allowing archive-controlled linkage to external files.

This issue has been fixed in commit e2b9cbdd3354d2b1569b7390d1bc15c1930559ad
Published: 2026-08-10
Score: 4.6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GNU cpio’s tar extraction routine sanitizes file names but omits sanitation for hard‑link targets when the --no-absolute-filenames option is used. An archive supplied by an attacker that contains a hard‑link entry with a linkname pointing to an absolute path outside the extraction directory causes cpio to create a hard link to that external file. This bypasses the intended restriction and allows the attacker to create or expose a link to any file that cpio can reach with its current permissions, potentially enabling the attacker to read or modify that file through the newly created link.

Affected Systems

The vulnerability affects all GNU cpio versions prior to the revision identified by commit e2b9cbdd3354d2b1569b7390d1bc15c1930559ad. Systems running older releases of the cpio utility—regardless of the operating system—are impacted.

Risk and Exploitability

The CVSS score of 4.6 indicates moderate complexity and scope; the exploit requires the ability to provide a crafted tar file to a running instance of cpio. Because the attack relies on local access to cpio, it is most relevant to users with local privileges and is not listed in the CISA KEV catalog. No EPSS data is available, suggesting that the exploit probability is not well characterized yet. Given the lack of known public exploitation, the risk is considered moderate, but any system that processes untrusted archives with cpio should treat this as a potential threat.

Generated by OpenCVE AI on August 10, 2026 at 11:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update GNU cpio to a version that includes commit e2b9cbdd3354d2b1569b7390d1bc15c1930559ad or later.
  • If an update is not immediately possible, avoid using the --no-absolute-filenames option with cpio or use an alternative extraction tool that properly validates hard‑link targets when handling tar archives.
  • Restrict untrusted tar archive extraction to non‑privileged users and enforce file system permissions to prevent unintended access to sensitive files.

Generated by OpenCVE AI on August 10, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Description GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar hard-link target is passed to the link_to_name function without equivalent sanitization before calling link function. A tar archive provided by an attacker, containing a hard-link entry whose linkname is set to an absolute path outside the extraction directory, can cause cpio to create a hard link to an existing file outside the intended extraction directory, breaking the expected guarantee of --no-absolute-filenames and allowing archive-controlled linkage to external files. This issue has been fixed in commit e2b9cbdd3354d2b1569b7390d1bc15c1930559ad
Title Path Traversal in GNU cpio
First Time appeared Gnu
Gnu cpio
Weaknesses CWE-22
CPEs cpe:2.3:a:gnu:cpio:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu cpio
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-08-10T10:57:14.423Z

Reserved: 2026-07-27T11:32:08.682Z

Link: CVE-2026-66484

cve-icon Vulnrichment

Updated: 2026-08-10T10:57:10.205Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T11:30:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')