Canonical Ubuntu Server 22.04 LTS (Jammy Jellyfish) Update Version cpio 2.13+dfsg-7ubuntu0.2
Your rating
Rate update installation process
Risk factor
No ratings yet. Be the first to rate this update.
AI enhanced content
Update Summary
USN-8704-1 updates GNU cpio on Ubuntu Server 22.04 LTS (jammy) to address three security issues: unsafe hard-link handling, stack memory bounds issues, and unsafe archive-name escaping. The affected package version is cpio 2.13+dfsg-7ubuntu0.2. Reference IDs: CVE-2026-66484, CVE-2026-66485, CVE-2026-66486.
Update Details
Security
- Fixes CVE-2026-66484: cpio could create hard links outside the extraction directory when extracting crafted tar archives, even with
--no-absolute-filenames. - Fixes CVE-2026-66485: cpio could crash due to improper bounds handling of stack memory used for pathnames during archive extraction.
- Fixes CVE-2026-66486: cpio could emit unsafe or misleading terminal output when listing crafted archive member names.
Hints
- A standard system update installs the fixed package version.
- For Ubuntu Server 22.04 LTS (jammy), update
cpioto2.13+dfsg-7ubuntu0.2.
Product Information
Vendor: Canonical
Product: Ubuntu Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: 22.04 LTS (Jammy Jellyfish)
Version: cpio 2.13+dfsg-7ubuntu0.2
Vendor release date: Aug 31, 2026
Original release notes: View on vendor site
Published on updatealert.io: Sep 2, 2026
Description: Server operating system for Linux infrastructure and workloads.