CVE-2026-54727
Received Received - Intake

Hardlink Arbitrary File Copy in proot-distro

Vulnerability report for CVE-2026-54727, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: GitHub, Inc.

Description

proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did not verify that the hardlink source container matched the destination container being restored, allowing a crafted restore archive to copy files between otherwise isolated containers. This issue is fixed in version 5.1.6.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
proot-distro proot-distro to 5.1.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-668 The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

proot-distro before version 5.1.6 has a vulnerability in the restore function where hardlink entries could reference files from other installed containers without verification. This allows a malicious restore archive to copy files between otherwise isolated containers, breaking container separation.

Impact Analysis

This vulnerability could allow an attacker to access or modify files in containers they should not have access to. If you use proot-distro to manage containers, an attacker might exploit this to steal data, escalate privileges, or compromise other containers on your system.

Compliance Impact

This vulnerability could lead to unauthorized data access or disclosure, violating confidentiality requirements in GDPR and HIPAA. It may result in non-compliance if sensitive data is exposed between containers, potentially leading to legal or regulatory penalties.

Mitigation Strategies

Update proot-distro to version 5.1.6 or later to address the vulnerability. Avoid using untrusted restore archives that may contain hardlink entries referencing other containers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54727. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart