CVE-2026-66486

Public on 2026-08-10
Modified on 2026-08-12
Description
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing member names with embedded newline characters or ANSI escape sequences, causing forged listing entries or terminal control sequence injection when the listing is displayed.




This issue has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30
Severity
Low severity
Low
See what this means
CVSS v3 Base Score
3.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core cpio Pending Fix
Amazon Linux 2023 cpio Pending Fix
Amazon Linux 2 - Core libarchive Not Affected
Amazon Linux 2023 libarchive Not Affected
Amazon Linux 2 - Core python-cpio Not Affected
Amazon Linux 2023 python-cpio Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N