CVE-2026-77113 PUBLISHED

Path Traversal Vulnerability in apport-unpack

Assigner: canonical
Reserved: 20.08.2026 Published: 20.08.2026 Updated: 20.08.2026

Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.7

Product Status

Vendor Canonical
Product Apport
Versions Default: unaffected
  • affected from 0 to 2.36.0 (excl.)
  • affected from 0 to 2.34.2 (excl.)
  • affected from 0 to 2.28.4 (excl.)

Credits

  • Sakib Sarkar (0xROI) finder

References

Problem Types

  • CWE-23 Relative path traversal CWE

Impacts

  • CAPEC-126 Path Traversal