CVE-2015-1197: GNU Cpio

Low severity, CVSS 1.9. EPSS: 2.9% chance of exploitation in the next 30 days.

cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.

Affected products

  • GNU Cpio: version 2.11 only

Published 2015-02-19. Last modified 2026-06-17.