Views
6

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

USN-8704-1 updates GNU cpio on Ubuntu Server 22.04 LTS (jammy) to address three security issues: unsafe hard-link handling, stack memory bounds issues, and unsafe archive-name escaping. The affected package version is cpio 2.13+dfsg-7ubuntu0.2. Reference IDs: CVE-2026-66484, CVE-2026-66485, CVE-2026-66486.

Update Details

Security

  • Fixes CVE-2026-66484: cpio could create hard links outside the extraction directory when extracting crafted tar archives, even with --no-absolute-filenames.
  • Fixes CVE-2026-66485: cpio could crash due to improper bounds handling of stack memory used for pathnames during archive extraction.
  • Fixes CVE-2026-66486: cpio could emit unsafe or misleading terminal output when listing crafted archive member names.

Hints

  • A standard system update installs the fixed package version.
  • For Ubuntu Server 22.04 LTS (jammy), update cpio to 2.13+dfsg-7ubuntu0.2.

Product Information

Vendor: Canonical

Product: Ubuntu Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: 22.04 LTS (Jammy Jellyfish)

Version: cpio 2.13+dfsg-7ubuntu0.2

Vendor release date: Aug 31, 2026

Original release notes: View on vendor site

Published on updatealert.io: Sep 2, 2026

Description: Server operating system for Linux infrastructure and workloads.