GNU cpio is prone to an overflow condition. The program fails to properly sanitize user-supplied input resulting in a heap overflow. With a specially crafted response or file, a remote attacker can potentially cause arbitrary code execution.
Upgrade to version 2.11 or higher, as it has been reported to fix this vulnerability. Users are advised not to connect to untrusted rmt servers before upgrading.