CVE-2026-66484 | GNU Cpio up to 2.15 Tar Archive Extraction link_to_name path traversal

SecurityVulns

A vulnerability has been found in GNU Cpio up to 2.15 and classified as problematic. The impacted element is the function link_to_name of the component Tar Archive Extraction. The manipulation leads to path traversal.

This vulnerability is listed as CVE-2026-66484. The attack may be initiated remotely. There is no available exploit.

It is recommended to apply a patch to fix this issue.VulDB Recent EntriesRead More