PT-2026-69442 · Gnu+2 · Gnu Cpio+2

CVE-2026-66486

·

Published

2026-08-10

·

Updated

2026-09-03

CVSS v4.0

4.6

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GNU cpio (affected versions not specified)
Description Improper encoding or escaping of output occurs in the archive member listing functionality. When listing archive members using the cpio -it command, member names are printed directly to the output without quoting or escaping. This allows an attacker to create a cpio archive with member names containing embedded newline characters or ANSI escape sequences, leading to forged listing entries or terminal control sequence injection when the listing is displayed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-94689
CVE-2026-66486
OESA-2026-3540
OPENSUSE-SU-2026:11618-1
OPENSUSE-SU-2026:21747-1
SUSE-SU-2026:23355-1
USN-8704-1

Affected Products

Gnu Cpio
Linuxmint
Ubuntu