Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94692.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94692
Upstream
  • CVE-2026-66485
Published
2026-08-10T11:17:27Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-66485 affecting package cpio 2.14-1
Details

GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled pathname during extraction. A malicious cpio archive containing a sufficiently long nested pathname causes an unbounded stack allocation, resulting in a stack overflow and crash of the cpio process. An attacker who can supply a crafted cpio archive to a victim who extracts it can cause a denial of service.

This issue has been fixed in commit 3cd514031371d8aeeaf2048aa10103e02831aaa9

References

Affected packages

Azure Linux:3 / cpio

Package

Name
cpio
Purl
pkg:rpm/azure-linux/cpio

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.14-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94692.json"