GNU cpio through 2.13 allows attackers to execute arbitrary code via a
crafted pattern file, because of a dstring.c ds_fgetstr integer overflow
that triggers an out-of-bounds heap write. (CVE-2021-38185).
- https://bugs.mageia.org/show_bug.cgi?id=29366
- https://lists.suse.com/pipermail/sle-security-updates/2021-August/009282.html
-
- https://ubuntu.com/security/notices/USN-5064-1
- https://www.cve.org/CVERecord?id=CVE-2021-38185
- 8/core/cpio-2.13-5.1.mga8
Get the latest Linux and open source security news straight to your inbox.