What is CVE-2026-66484?
A Path Traversal vulnerability has been identified in GNU cpio's tar archive extraction in copy-in mode when using the --no-absolute-filenames option. The hard-link target is not properly normalized, potentially allowing an attacker to write files outside the intended directory. Users should avoid extracting untrusted tar archives until a patch is applied.
Azərbaycanca: GNU cpio utilitində tar arxivinin çıxarılması zamanı (copy-in rejimində, --no-absolute-filenames seçimi ilə) Path Traversal zəifliyi aşkarlanıb. Hard-link hədəfi adekvat normallaşdırılmadığı üçün təcavüzkar məhdudlaşdırılmış qovluqdan kənara yaza bilər. İstifadəçilərə yeniləmə tətbiq edilənə qədər etibarsız tar arxivlərini çıxarmamaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which mode does the CVE-2026-66484 vulnerability occur in the GNU cpio utility?
This Path Traversal vulnerability occurs in GNU cpio during tar archive extraction in copy-in mode when the --no-absolute-filenames option is used.
What measure is recommended to protect against CVE-2026-66484 until a patch is applied?
Users are advised to avoid extracting tar archives from untrusted sources until a patch is applied.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.