Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.
CVSS Details
- CVSS 3.1 Base Score: 4.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade cpioNo solution exists | May 15, 2025 | Feb 29, 2024 |
| Dell Powerstore Dsa2024398 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Sep 17, 2024 |
| Dell Powerstore Dsa2024408 | — | Upgrade Dell PowerStoreOS to the latest version | Jan 13, 2026 | Sep 26, 2024 |
| Dell Powerstore Dsa2024432 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Oct 29, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 29, 2024 |
| Suse | — | Upgrade cpio-langUpgrade cpio-mtUpgrade cpio | Jan 29, 2024 | Jan 27, 2024 |
| Ubuntu | — | Upgrade cpio | Apr 30, 2024 | Feb 29, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | Jan 5, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub