cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade cpio | Aug 22, 2024 | Feb 19, 2015 |
| Amazon Linux Ami 2 | — | Upgrade cpio-debuginfoUpgrade cpio | Mar 5, 2024 | Feb 19, 2015 |
| Amazon_linux | — | Upgrade cpio | Mar 5, 2024 | Feb 19, 2015 |
| Amazon_linux_2023 | — | Upgrade cpio-debuginfoUpgrade cpio-debugsourceUpgrade cpio | Feb 17, 2025 | Feb 19, 2015 |
| Debian | — | Upgrade cpio | Jul 30, 2024 | Feb 19, 2015 |
| Freebsd | — | Upgrade gcpio | Dec 10, 2025 | Mar 31, 2015 |
| Gentoo Linux | — | Upgrade app-arch/cpio. | Oct 30, 2017 | Feb 19, 2015 |
| Huawei Euleros 2_0_sp1 | — | Upgrade cpio | Nov 30, 2017 | Feb 19, 2015 |
| Huawei Euleros 2_0_sp10 | — | Upgrade cpio | Jan 10, 2024 | Feb 19, 2015 |
| Huawei Euleros 2_0_sp11 | — | Upgrade cpio | Jan 10, 2024 | Feb 19, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 5, 2015 |
| Suse | — | Upgrade cpio-langUpgrade cpioUpgrade cpio-mt | Aug 9, 2024 | Feb 19, 2015 |
| Ubuntu | — | Upgrade cpio | Feb 22, 2016 | Feb 19, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub