{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos7els/vex/2026/cve-2026-66486-els_os-centos7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-14T14:43:24Z",
      "generator": {
        "date": "2026-08-14T14:43:23Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-66486-ELS_OS-CENTOS7ELS",
      "initial_release_date": "2026-08-10T11:17:00Z",
      "revision_history": [
        {
          "date": "2026-08-10T11:17:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-13T12:45:29Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-08-14T14:43:24Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-66486"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 7",
                "product": {
                  "name": "Community Enterprise Operating System 7",
                  "product_id": "CentOS-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "cpio-0:2.11-28.el7.x86_64",
                "product": {
                  "name": "cpio-0:2.11-28.el7.x86_64",
                  "product_id": "cpio-0:2.11-28.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/cpio@2.11-28.el7?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "cpio-0:2.11-28.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "cpio-0:2.11-28.el7.tuxcare.els1.x86_64",
                  "product_id": "cpio-0:2.11-28.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/cpio@2.11-28.el7.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cpio-0:2.11-28.el7.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:cpio-0:2.11-28.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "cpio-0:2.11-28.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cpio-0:2.11-28.el7.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:cpio-0:2.11-28.el7.x86_64"
        },
        "product_reference": "cpio-0:2.11-28.el7.x86_64",
        "relates_to_product_reference": "CentOS-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-66486",
      "cwe": {
        "id": "CWE-116",
        "name": "Improper Encoding or Escaping of Output"
      },
      "notes": [
        {
          "category": "description",
          "text": "GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing member names with embedded newline characters or ANSI escape sequences, causing forged listing entries or terminal control sequence injection when the listing is displayed.\n\n\n\n\nThis issue has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "CentOS-7:cpio-0:2.11-28.el7.tuxcare.els1.x86_64",
          "CentOS-7:cpio-0:2.11-28.el7.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-66486"
        },
        {
          "category": "external",
          "summary": "https://cert.pl/en/posts/2026/08/CVE-2026-66484",
          "url": "https://cert.pl/en/posts/2026/08/CVE-2026-66484"
        },
        {
          "category": "external",
          "summary": "https://git.savannah.gnu.org/cgit/cpio.git",
          "url": "https://git.savannah.gnu.org/cgit/cpio.git"
        }
      ],
      "release_date": "2026-08-10T11:17:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-14T10:44:17.102977Z",
          "details": "Deprioritize: the flaw only affects the interactive listing path (cpio -it) and requires a user to view an attacker-supplied archive; it does not impact extraction, execution, or the filesystem, and carries no confidentiality or availability impact. Its effect is limited to forged listing text or ANSI control sequences in the invoking user’s terminal session; when output is redirected to logs or parsed by automation rather than rendered in a TTY, these sequences are inert. Given the required user interaction and the low, terminal-only integrity impact (no code execution), this is a low-priority issue for managed server and VM environments.",
          "product_ids": [
            "CentOS-7:cpio-0:2.11-28.el7.tuxcare.els1.x86_64",
            "CentOS-7:cpio-0:2.11-28.el7.x86_64"
          ]
        }
      ]
    }
  ]
}