[Git][security-tracker-team/security-tracker][master] Add Debian bug references for cpio issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 15:36:23 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
32936dd6 by Salvatore Bonaccorso at 2026-08-14T16:35:29+02:00
Add Debian bug references for cpio issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5445,17 +5445,17 @@ CVE-2026-66738 (SPIP before 4.4.18 contains a code injection vulnerability in SQ
 CVE-2026-66642 (Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows  ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66486 (GNU cpio is vulnerable to improper encoding or escaping of output in i ...)
-	- cpio <unfixed>
+	- cpio <unfixed> (bug #1144387)
 	[trixie] - cpio <no-dsa> (Minor issue)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-66484
 	NOTE: Fixed by: https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=2ff9600c9ef32e88759843cdbde74c8db5ae9b30
 CVE-2026-66485 (GNU cpio is vulnerable to an uncontrolled memory allocation in the mak ...)
-	- cpio <unfixed>
+	- cpio <unfixed> (bug #1144387)
 	[trixie] - cpio <no-dsa> (Minor issue)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-66484
 	NOTE: Fixed by: https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=3cd514031371d8aeeaf2048aa10103e02831aaa9
 CVE-2026-66484 (GNU cpio contains a Path Traversal vulnerability in its tar archive ex ...)
-	- cpio <unfixed>
+	- cpio <unfixed> (bug #1144387)
 	[trixie] - cpio <no-dsa> (Minor issue)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-66484
 	NOTE: Fixed by: https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=e2b9cbdd3354d2b1569b7390d1bc15c1930559ad



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/32936dd677412d5e6f61f6e5e3f2260a46b63839

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/32936dd677412d5e6f61f6e5e3f2260a46b63839
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/c72657b9/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list