{
  "document": {
    "aggregate_severity": {
      "text": "Moderate"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2026-66485: avoid stack exhaustion from archive-controlled paths\n- CVE-2026-66486: quote file names in diagnostics and listings",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787310466",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787310466"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/tuxcare9.6esu/advisories/2026/clsa-2026_1787310466.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-21T11:08:31Z",
      "generator": {
        "date": "2026-08-21T11:08:31Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1787310466",
      "initial_release_date": "2026-08-21T11:08:31Z",
      "revision_history": [
        {
          "date": "2026-08-21T11:08:31Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "cpio: Fix of 2 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "AlmaLinux 9.6",
                "product": {
                  "name": "AlmaLinux 9.6",
                  "product_id": "AlmaLinux-9.6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:almalinux:almalinux:9.6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "AlmaLinux"
          }
        ],
        "category": "vendor",
        "name": "AlmaLinux OS Foundation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Rocky Linux 9.6",
                "product": {
                  "name": "Rocky Linux 9.6",
                  "product_id": "Rocky Linux-9.6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:resf:rocky_linux:9.6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Rocky Linux"
          }
        ],
        "category": "vendor",
        "name": "Rocky Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64",
                "product": {
                  "name": "cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64",
                  "product_id": "cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/cpio@2.13-16.el9_6.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64",
                "product": {
                  "name": "cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64",
                  "product_id": "cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/cpio@2.13-16.el9_6.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64"
        },
        "product_reference": "cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64"
        },
        "product_reference": "cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64"
        },
        "product_reference": "cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64"
        },
        "product_reference": "cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-66485",
      "cwe": {
        "id": "CWE-789",
        "name": "Memory Allocation with Excessive Size Value"
      },
      "notes": [
        {
          "category": "description",
          "text": "GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled pathname during extraction. A malicious cpio archive containing a sufficiently long nested pathname causes an unbounded stack allocation, resulting in a stack overflow and crash of the cpio process. An attacker who can supply a crafted cpio archive to a victim who extracts it can cause a denial of service.\n\nThis issue has been fixed in commit 3cd514031371d8aeeaf2048aa10103e02831aaa9",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64",
          "Rocky Linux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-66485"
        },
        {
          "category": "external",
          "summary": "https://cert.pl/en/posts/2026/08/CVE-2026-66484",
          "url": "https://cert.pl/en/posts/2026/08/CVE-2026-66484"
        },
        {
          "category": "external",
          "summary": "https://git.savannah.gnu.org/cgit/cpio.git",
          "url": "https://git.savannah.gnu.org/cgit/cpio.git"
        }
      ],
      "release_date": "2026-08-10T11:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-21T11:07:49.777967Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787310466",
          "product_ids": [
            "AlmaLinux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787310466"
        },
        {
          "category": "none_available",
          "date": "2026-08-10T11:17:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64",
            "Rocky Linux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-66486",
      "cwe": {
        "id": "CWE-116",
        "name": "Improper Encoding or Escaping of Output"
      },
      "notes": [
        {
          "category": "description",
          "text": "GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing member names with embedded newline characters or ANSI escape sequences, causing forged listing entries or terminal control sequence injection when the listing is displayed.\n\n\n\n\nThis issue has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64",
          "Rocky Linux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-66486"
        },
        {
          "category": "external",
          "summary": "https://cert.pl/en/posts/2026/08/CVE-2026-66484",
          "url": "https://cert.pl/en/posts/2026/08/CVE-2026-66484"
        },
        {
          "category": "external",
          "summary": "https://git.savannah.gnu.org/cgit/cpio.git",
          "url": "https://git.savannah.gnu.org/cgit/cpio.git"
        }
      ],
      "release_date": "2026-08-10T11:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-21T11:07:49.777967Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1787310466",
          "product_ids": [
            "AlmaLinux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els2.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1787310466"
        },
        {
          "category": "none_available",
          "date": "2026-08-10T11:17:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64",
            "Rocky Linux-9.6:cpio-0:2.13-16.el9_6.tuxcare.els1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}