What is CVE-2026-54574?
CVE-2026-54574 is a vulnerability in the `proot-distro` utility. Prior to version 5.1.5, plain tarball root filesystems (`_extract_plain_tar()`) and Docker layers (`_apply_layer()`) are extracted without proper validation, potentially allowing malicious file placement. Immediate update to version 5.1.5 or later is strongly recommended to mitigate this issue.
Azərbaycanca: CVE-2026-54574, `proot-distro` utilitində aşkarlanan boşluqdur. 5.1.5 versiyasından əvvəl, arxiv faylları (`_extract_plain_tar()`) və Docker layları (`_apply_layer()`) çıxarılarkən yoxlama aparılmır ki, bu da zərərverici faylların sistemə yerləşdirilməsinə səbəb ola bilər. Təhlükəsizlik üçün dərhal 5.1.5 və ya daha yeni versiyaya yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of the `proot-distro` utility are affected by CVE-2026-54574?
This vulnerability affects all versions of the `proot-distro` utility prior to version 5.1.5.
What should be done to mitigate CVE-2026-54574?
To mitigate the vulnerability, it is strongly recommended to immediately update the `proot-distro` utility to version 5.1.5 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.