[CLSA-2026:1786620962] cpio: Fix of CVE-2023-7207
Type:
security
Severity:
Moderate
Release date:
2026-08-13 11:36:12 UTC
Description:
- CVE-2023-7207: path traversal via absolute symlink targets under --no-absolute-filenames; drop cpio-2.13-revert-CVE-2015-1197-fix.patch and apply the upstream symlink-placeholder fix instead
CVEs fixed:
Updated packages:
  • cpio-2.13-16.el9_2.tuxcare.els1.x86_64.rpm
    sha:8bdc644a471e8a943c1fc7ee9334413fd82ecf01c35b0730650f2ba4abafb343
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.