CVE-2026-66486
Public on 2026-08-10
Modified on 2026-08-12
Description
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing member names with embedded newline characters or ANSI escape sequences, causing forged listing entries or terminal control sequence injection when the listing is displayed.
This issue has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30
This issue has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | cpio | Pending Fix | ||
| Amazon Linux 2023 | cpio | Pending Fix | ||
| Amazon Linux 2 - Core | libarchive | Not Affected | ||
| Amazon Linux 2023 | libarchive | Not Affected | ||
| Amazon Linux 2 - Core | python-cpio | Not Affected | ||
| Amazon Linux 2023 | python-cpio | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 3.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |