[CLSA-2026:1790934009] cpio: Fix of CVE-2023-7207
Type:
security
Severity:
Moderate
Release date:
2026-10-02 09:51:05 UTC
Description:
- Add Alma9_8ESU; carry the tuxcare9.6esu CVE fixes - CVE-2023-7207: path traversal via absolute symlink targets under --no-absolute-filenames; drop cpio-2.13-revert-CVE-2015-1197-fix.patch and apply the upstream symlink-placeholder fix instead - CVE-2026-66485: avoid stack exhaustion from archive-controlled paths - CVE-2026-66486: quote file names in diagnostics and listings
CVEs fixed:
Updated packages:
  • cpio-2.13-16.el9.tuxcare.els3.aarch64.rpm
    sha:cafb45dd8d74b4d6c5318eec7eddd139bfb76c1ada2ab5b1472040e932cf6a65
  • cpio-2.13-16.el9.tuxcare.els3.i686.rpm
    sha:0ffefe689c437ea676786f26fa9ce28ffb7d856d3bbb4500fb6fb2a9b0ba2dae
  • cpio-2.13-16.el9.tuxcare.els3.x86_64.rpm
    sha:8251c7513fb9ea88a09c122723b0b725626dfecbebbae13298923100069aa3f1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.