CVE-2026-66485 | GNU cpio up to 2.15 src/makepath.c make_path stack-based overflow

SecurityVulns

A vulnerability, which was classified as problematic, was found in GNU cpio up to 2.15. The affected element is the function make_path of the file src/makepath.c. Executing a manipulation can lead to stack-based buffer overflow.

This vulnerability is tracked as CVE-2026-66485. The attack can be launched remotely. No exploit exists.

It is best practice to apply a patch to resolve this issue.VulDB Recent EntriesRead More