Affected Component Package: proot-distro Affected command: restore Attack surface: Host-side Termux CLI processing a user-supplied backup archive Vulnerability type: Container Isolation Bypass / Cross-Container Read and…
| CVE ID | CVE-2026-54727 |
| Vendor | pip |
| Affected Product | proot-distro |
| Vulnerability Type | Vulnerability |
| CVSS Score | 8.2 (HIGH) |
| Actively Exploited | ❌ No known exploitation |
| Patch Status | See Vendor Advisory → |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via github_advisories) |
#
restore| ## Affected Versions | Component | Version |
|---|---|---|
| proot-distro | 5.1.5 (confirmed affected) | |
| Test distro | Alpine Linux | |
| Architecture | aarch64 | |
| Device | Samsung Galaxy A23 | |
| Package source | https://packages-cf.termux.dev/apt/termux-main stable/main aarch64 | --- |
proot-distro restore accepts hardlink entries whose source path references a different installed container. The restore logic resolves the hardlink source from the archive's linkname field and copies thSigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.