Repository: termux/proot-distro Component: proot_distro/commands/install.py → _extract_plain_tar(); also helpers/docker.py → _apply_layer() --Affected Versions | Component | Version | |---------------|------------------…
| CVE ID | CVE-2026-54574 |
| Vendor | pip |
| Affected Product | proot-distro |
| Vulnerability Type | Vulnerability |
| CVSS Score | 8.2 (HIGH) |
| Actively Exploited | ❌ No known exploitation |
| Patch Status | See Vendor Advisory → |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via github_advisories) |
Repository: termux/proot-distro Component: proot_distro/commands/install.py → _extract_plain_tar(); also helpers/docker.py → _apply_layer() ---
| ## Affected Versions | Component | Version |
|---|---|---|
| proot-distro | 5.0.2 (confirmed vulnerable) | |
| Termux app | 0.119.0-beta.3 | |
| Device / ABI | Samsung Galaxy A23 / aarch64 | |
| Python (host) | 3.13 | --- |
proot-distro install extracts a plain tarball rootfs by calling _extract_plain_tar() inproot_distro/commands/install.py. This function correctly rejects tar member names containing .. components, but applies no equivalent check on symlink targets (member.linkname). A tar archive can therefore: 1. Plant a symlink inside the rootfs whose t
Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.