{"id":"AZL-94692","summary":"CVE-2026-66485 affecting package cpio 2.14-1","details":"GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled pathname during extraction. A malicious cpio archive containing a sufficiently long nested pathname causes an unbounded stack allocation, resulting in a stack overflow and crash of the cpio process. An attacker who can supply a crafted cpio archive to a victim who extracts it can cause a denial of service.\n\nThis issue has been fixed in commit 3cd514031371d8aeeaf2048aa10103e02831aaa9","modified":"2026-08-30T05:26:50Z","published":"2026-08-10T11:17:27Z","upstream":["CVE-2026-66485"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66485"}],"affected":[{"package":{"name":"cpio","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/cpio"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.14-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94692.json"}}],"schema_version":"1.9.0"}