UbuntuUpdates.org

Package "cpio"

Name: cpio

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • GNU cpio -- a program to manage archives of files (win32 build)

Latest version: 2.13+dfsg-7ubuntu0.2
Release: jammy (22.04)
Level: updates
Repository: universe

Links



Other versions of "cpio" in Jammy

Repository Area Version
base main 2.13+dfsg-7
base universe 2.13+dfsg-7
security main 2.13+dfsg-7ubuntu0.2
security universe 2.13+dfsg-7ubuntu0.2
updates main 2.13+dfsg-7ubuntu0.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.13+dfsg-7ubuntu0.2 2026-08-31 18:07:34 UTC

cpio (2.13+dfsg-7ubuntu0.2) jammy-security; urgency=medium

  * SECURITY UPDATE: Unbounded stack allocation
    - debian/patches/CVE-2026-66485.patch: Minor fixes in src/makepath.c,
      src/userspec.c.
    - CVE-2026-66485
  * SECURITY UPDATE: Hard link to file outside intended directory
    - debian/patches/CVE-2026-66484.patch: The --no-absolute-filenames option
      affects hard link targets too. in src/tar.c.
    - CVE-2026-66484
  * SECURITY UPDATE: Unescaped output
    - debian/patches/CVE-2026-66486.patch: Quote file names in error messages
      and in listings. in src/copyin.c, src/copyout.c, src/copypass.c,
      src/main.c, tests/CVE-2019-14866.at, tests/testsuite.
    - CVE-2026-66486

 -- Isabel Garcia Contreras Tue, 18 Aug 2026 16:46:57 -0400

Source diff to previous version
CVE-2026-66485 GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack m
CVE-2026-66484 GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the
CVE-2026-66486 GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio
CVE-2019-14866 In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives fro

Version: 2.13+dfsg-7ubuntu0.1 2024-04-29 13:07:02 UTC

  cpio (2.13+dfsg-7ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: Path traversal vulnerability
    - debian/patches/CVE-2023-7207.patch: Create symlink placeholder
      if --no-absolute-filenames was given and replace placeholders
      after extraction.
    - debian/patches/revert-CVE-2015-1197-handling.patch: Removed.
    - CVE-2023-7207

 -- Fabian Toepfer <email address hidden> Sun, 28 Apr 2024 14:30:36 +0200

CVE-2023-7207 Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in
CVE-2015-1197 cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive



About   -   Send Feedback to @ubuntu_updates