Vendor
high
advisory
Proot-Distro Container Isolation Bypass via Crafted Restore Archive
1 TTPThe proot-distro package fails to validate container boundaries during the restoration of archive files, allowing attackers to perform cross-container file disclosure and injection.
proot-distro
container-isolation
sandbox-escape
privilege-escalation
android
1t
high
advisory
Arbitrary Host File Write via Symlink Escape in proot-distro
2 TTPs 1 IOCThe proot-distro utility contains a symlink traversal vulnerability (CVE-2026-54574) that allows malicious tar archives to overwrite arbitrary files on the host filesystem during the installation or reset process.
proot-distro +1
vulnerability
path-traversal
arbitrary-file-write
termux
2t
1i