


Perceptive Security
SOC/SIEM Consultancy

proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_…
Published:
28 juli 2026 om 22:00:00
Alert date:
29 juli 2026 om 18:02:14
Source:
nvd.nist.gov
Mobile & IoT, Supply Chain & Dependencies, Zero-Day Vulnerabilities
CVE-2026-54574 affects proot-distro, a utility for managing proot containers, in versions prior to 5.1.5. The vulnerability exists in two functions: _extract_plain_tar() in install.py and _apply_layer() in docker.py, both of which fail to validate archive-controlled symlink targets in member.linkname fields. A malicious archive can exploit this by planting an absolute host-path symlink, allowing arbitrary file writes to the host filesystem outside the container boundary. This constitutes a container escape/path traversal vulnerability that could lead to host system compromise. The attack vector requires a user to install a malicious proot-distro package or Docker layer. The issue has been patched in version 5.1.5, released by the Termux project. Users are advised to upgrade immediately to mitigate the risk of host filesystem tampering.
Technical details
Mitigation steps:
Affected products:
proot-distro (versions prior to 5.1.5)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54574
https://github.com/termux/proot-distro/commit/a96d7a9667f38e45d812614852ee3915d1c0ae45
https://github.com/termux/proot-distro/releases/tag/v5.1.5
https://github.com/termux/proot-distro/security/advisories/GHSA-9xq3-3fqg-4vg7
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
