HomeCVE Intelligence › CVE-2026-54727
CVSS 8.2 HIGH Vulnerability

CVE-2026-54727: proot-distro has a Container Isolation Bypass via Crafted Restore Archive

Affected Component Package: proot-distro Affected command: restore Attack surface: Host-side Termux CLI processing a user-supplied backup archive Vulnerability type: Container Isolation Bypass / Cross-Container Read and…

8.2CVSS Score
HIGHSeverity
NOCISA KEV
VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-54727
Vendorpip
Affected Productproot-distro
Vulnerability TypeVulnerability
CVSS Score8.2 (HIGH)
Actively Exploited❌ No known exploitation
Patch StatusSee Vendor Advisory →
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via github_advisories)

🔬 Technical Analysis

#

Affected Component - Package: proot-distro

Affected command: restore
Attack surface: Host-side Termux CLI processing a user-supplied backup archive
Vulnerability type: Container Isolation Bypass / Cross-Container Read and Write ---
## Affected VersionsComponentVersion
proot-distro5.1.5 (confirmed affected)
Test distroAlpine Linux
Architectureaarch64
DeviceSamsung Galaxy A23
Package sourcehttps://packages-cf.termux.dev/apt/termux-main stable/main aarch64---

Summary When restoring a crafted backup archive, proot-distro restore accepts hardlink entries whose source path references a different installed container. The restore logic resolves the hardlink source from the archive's linkname field and copies th

🎯 Known Indicators of Compromise

{"type":"url","value":"https://packages-cf.termux.dev/apt/termux-main","confidence_score":0.82,"first_seen":"2026-07-29","source_count":1}

📚 Advisory References

⚡ DETECTION RULES AVAILABLE

Get CVE-2026-54727 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence