CVE-2026-54574 | termux proot-distro up to 5.1.4 Archive Extraction/Docker Layer Application docker.py _extract_plain_tar/_apply_layer member.linkname symlink

SecurityVulns

A vulnerability identified as problematic has been detected in termux proot-distro up to 5.1.4. This vulnerability affects the function _extract_plain_tar/_apply_layer of the file proot_distro/commands/install.py/proot_distro/helpers/docker.py of the component Archive Extraction/Docker Layer Application. This manipulation of the argument member.linkname causes symlink following.

This vulnerability is handled as CVE-2026-54574. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More