| Release | Version |
|---|---|
| bullseye | 2.13+dfsg-7.1~deb11u1 |
| bookworm | 2.13+dfsg-7.1 |
| trixie | 2.15+dfsg-2 |
| forky | 2.15+dfsg-2.1 |
| sid | 2.15+dfsg-2.1 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2026-66486 | vulnerable | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | GNU cpio is vulnerable to improper encoding or escaping of output in i ... |
| CVE-2026-66485 | vulnerable | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | GNU cpio is vulnerable to an uncontrolled memory allocation in the mak ... |
| CVE-2026-66484 | vulnerable | vulnerable | vulnerable (no DSA) | vulnerable | vulnerable | GNU cpio contains a Path Traversal vulnerability in its tar archive ex ... |
| CVE-2023-7207 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | fixed | Debian's cpio contains a path traversal vulnerability. This issue was ... |
| Bug | Description |
|---|---|
| CVE-2021-38185 | GNU cpio through 2.13 allows attackers to execute arbitrary code via a ... |
| CVE-2019-14866 | In all versions of cpio before 2.13 does not properly validate input f ... |
| CVE-2016-2037 | The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remo ... |
| CVE-2015-1197 | cpio 2.11, when using the --no-absolute-filenames option, allows local ... |
| CVE-2014-9112 | Heap-based buffer overflow in the process_copy_in function in GNU Cpio ... |
| CVE-2010-0624 | Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib. ... |
| CVE-2007-4476 | Buffer overflow in the safer_name_suffix function in GNU tar has unspe ... |
| CVE-2005-4268 | Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a ... |
| CVE-2005-1229 | Directory traversal vulnerability in cpio 2.6 and earlier allows remot ... |
| CVE-2005-1111 | Race condition in cpio 2.6 and earlier allows local users to modify pe ... |
| CVE-1999-1572 | cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operat ... |
| DSA / DLA | Description |
|---|---|
| DLA-3445-1 | cpio - security update |
| DLA-1981-1 | cpio - security update |
| DSA-3483-1 | cpio - security update |
| DLA-415-1 | cpio - security update |
| DSA-3111-1 | cpio - security update |
| DLA-111-1 | cpio - security update |
| DSA-1566-1 | cpio - programming error |
| DSA-846-1 | cpio - several |
| DSA-664-1 | cpio - broken file permissions |