CVE-2026-54727: Termux Proot-Distro

High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.

proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did not verify that the hardlink source container matched the destination container being restored, allowing a crafted restore archive to copy files between otherwise isolated containers. This issue is fixed in version 5.1.6.

Affected products

  • Termux Proot-Distro: before 5.1.6 (fixed in 5.1.6)

Published 2026-07-29. Last modified 2026-07-30.