Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade cpio | Jul 30, 2024 | May 2, 2005 |
| Freebsd | — | Upgrade FreeBSD | Dec 10, 2025 | Jan 27, 2006 |
| Gentoo Linux | — | Upgrade app-arch/cpio. | Oct 30, 2017 | May 2, 2005 |
| Suse | — | Upgrade cpio | Feb 17, 2015 | May 2, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub