{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/oraclelinux7els/vex/2023/cve-2023-7216-els_os-oraclelinux7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-03T13:46:46Z",
      "generator": {
        "date": "2026-08-03T13:46:45Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2023-7216-ELS_OS-ORACLELINUX7ELS",
      "initial_release_date": "2023-01-01T00:00:00Z",
      "revision_history": [
        {
          "date": "2023-01-01T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-01T22:58:31Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-08-03T13:46:46Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2023-7216"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Oracle Linux 7",
                "product": {
                  "name": "Oracle Linux 7",
                  "product_id": "Oracle-Linux-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Oracle Linux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "cpio-0:2.11-28.el7.x86_64",
                "product": {
                  "name": "cpio-0:2.11-28.el7.x86_64",
                  "product_id": "cpio-0:2.11-28.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/oracle/cpio@2.11-28.el7?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Oracle Corporation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "cpio-0:2.11-28.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "cpio-0:2.11-28.el7.tuxcare.els1.x86_64",
                  "product_id": "cpio-0:2.11-28.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/cpio@2.11-28.el7.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cpio-0:2.11-28.el7.tuxcare.els1.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:cpio-0:2.11-28.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "cpio-0:2.11-28.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cpio-0:2.11-28.el7.x86_64 as a component of Oracle Linux 7",
          "product_id": "Oracle-Linux-7:cpio-0:2.11-28.el7.x86_64"
        },
        "product_reference": "cpio-0:2.11-28.el7.x86_64",
        "relates_to_product_reference": "Oracle-Linux-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-7216",
      "cwe": {
        "id": "CWE-59",
        "name": "Improper Link Resolution Before File Access ('Link Following')"
      },
      "notes": [
        {
          "category": "description",
          "text": "A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in arbitrary directories through symlinks.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Oracle-Linux-7:cpio-0:2.11-28.el7.tuxcare.els1.x86_64",
          "Oracle-Linux-7:cpio-0:2.11-28.el7.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2023-7216"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2023-7216",
          "url": "https://access.redhat.com/security/cve/CVE-2023-7216"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2249901",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2249901"
        }
      ],
      "release_date": "2024-02-05T15:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-03T11:33:32.986616Z",
          "details": "This issue is only exploitable when a local user is tricked into extracting an attacker-supplied archive with cpio, i.e., it requires user interaction and is not reachable via a network service. Even then, it merely enables file writes via symlink traversal with the invoking user’s privileges, so it does not inherently provide privilege escalation or automatic code execution. Given these preconditions and the limited impact scope (C/I/A each low), it represents low practical risk in centrally managed server/VM environments and can be safely deprioritized.",
          "product_ids": [
            "Oracle-Linux-7:cpio-0:2.11-28.el7.tuxcare.els1.x86_64",
            "Oracle-Linux-7:cpio-0:2.11-28.el7.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "Oracle-Linux-7:cpio-0:2.11-28.el7.tuxcare.els1.x86_64",
            "Oracle-Linux-7:cpio-0:2.11-28.el7.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}