A cpio security update has been released for Debian GNU/Linux 8 and 9 Extended LTS to address two vulnerabilities.
ELA-863-1 cpio security update
Package : cpio
ELA-863-1 cpio security update
Version : 2.11+dfsg-4.1+deb8u4 (jessie), 2.11+dfsg-6+deb9u1 (stretch)
Related CVEs :
CVE-2019-14866
CVE-2021-38185
Improper validation of input was fixed in GNU cpio, a program to manage
archives of files.