CVE-2026-54727
proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did not verify that the hardlink source container matched the destination container being restored, allowing a crafted restore archive to copy files between otherwise isolated containers. This issue is fixed in version 5.1.6.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
- EPSS probability
- 0.12%
- CWE
- CWE-668
- Published
- 2026-07-29
- Last modified
- 2026-07-29
Affected products
- termux proot-distro
Weakness type
Related vulnerabilities
- CVE-2026-85053 — Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote...
- CVE-2026-82652 — SiYuan before v3.8.1 Information Disclosure via Publish Access
- CVE-2026-82650 — SiYuan before v3.8.1 Path Traversal via /api/template/render
- CVE-2026-72924 — GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default
- CVE-2026-79068 — Improper resource exposure in StreamsAPI in Google Chrome prior to 152.0.7977.65 allowed a remote...
- CVE-2026-79031 — Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote...
- CVE-2026-59308 — Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation
- CVE-2026-73843 — OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs