


Perceptive Security
SOC/SIEM Consultancy

proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced anothe…
Published:
29 July 2026 at 00:00:00
Alert date:
29 July 2026 at 20:02:14
Source:
nvd.nist.gov
Mobile & IoT, Cloud & Virtualization, Supply Chain & Dependencies
CVE-2026-54727 affects proot-distro, a utility for managing proot containers on Android/Termux environments. Prior to version 5.1.6, the restore functionality accepted hardlink entries without verifying that the hardlink source container matched the destination container being restored. This flaw allowed a crafted restore archive to copy files between otherwise isolated containers, breaking container isolation. The vulnerability could be exploited by an attacker who can supply a malicious restore archive. The issue has been patched in proot-distro version 5.1.6. Users are advised to update immediately to mitigate the risk of cross-container file access.
Technical details
Mitigation steps:
Affected products:
proot-distro
Termux proot-distro
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54727
https://github.com/termux/proot-distro/commit/98aff324b7d8500ff75a8ca9ac087ee636be4716
https://github.com/termux/proot-distro/releases/tag/v5.1.6
https://github.com/termux/proot-distro/security/advisories/GHSA-7h3g-4w2f-fj2f
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
