Vulnerabilities in LXD, Incus, Flatpak, GitLab, Radicle, the Linux kernel, WordPress, OpenVPN, NTFS-3G, FreeRDP, CUPS, and Dovecot

Several recently discovered vulnerabilities allow for root access within the system or achieve remote code execution.

  • 7 vulnerabilities in the LXD container management system and 11 vulnerabilities in the Incus fork. Several vulnerabilities, marked as critical, allow local unprivileged users to modify any files on the system or execute their code with root privileges. The vulnerabilities have been fixed in LXD versions 6.9, 5.21.8, 5.0.10, and 4.0.14, as well as in Incus 7.5.1. The issues were caused by incorrect handling of file paths, problems with symbolic links, and a lack of input validation in the code for migrating and backing up isolated environments or loading system images:
    • CVE-2026-85526 — arbitrary file overwrite in the system when processing a backup containing in subvolumes[].path a mount point path such as "../../../etc/cron.d".
    • CVE-2026-85185 — writing and deleting arbitrary files by specifying paths with "../" in btrfs subvolume names.
    • CVE-2026-87799 — writing to an arbitrary file in the system via symbolic link substitution during migration. of virtual machines.
    • CVE-2026-87798 — exceeding the base directory of the virtual machine during recursive file transmission.
    • CVE-2026-86334 — exceeding the base directory when exporting an image from external storage. server.
    • CVE-2026-86335 — access to private virtual machine images of other users.
    • CVE-2026-97335 — bypassing access restrictions to projects.
  • Vulnerabilities in the Flatpak self-contained packages system. Issues have been fixed in Flatpak version 1.18.1. Among the most dangerous vulnerabilities are:
    • CVE-2026-90616 — using symbolic links to bypass sandbox isolation and gain full access to the host filesystem;
    • Privilege escalation to root user via symbolic link substitution (CVE not assigned);
    • CVE-2026-9627 — writing files with root privileges through file path manipulation;
    • CVE-2026-96275 — writing files with root privileges via symbolic link manipulation;
    • CVE-2026-96276 — writing files with root privileges through the substitution of "../" in file paths while executing the command "flatpak build-init";
    • CVE-2026-96279 — reading arbitrary files in the primary system by creating a hard link when extracting an OCI archive.
    • CVE-2026-92162 — accessing files outside the base directory via substitution of "../" in DeployAppstream parameters.
    • CVE-2026-96280 — buffer overflow in the OCI delta update handler on 32-bit systems.
  • Two critical vulnerabilities in the collaboration platform GitLab that allow a remote authenticated user to execute their code on server by injecting a specially crafted regular expression into the CI/CD settings. The vulnerabilities reside in the regular expression parser and are caused by double free (CVE-2026-89078) and integer overflow (CVE-2026-93577). These issues have been addressed in releases 19.4.1, 19.3.3, and 19.2.7.
  • Two critical vulnerabilities in the network protocol used on nodes of the decentralized collaboration platform Radicle. The first vulnerability allows the viewing of data exchanged by nodes through traffic monitoring. The second vulnerability enables spoofing of the node identifier to gain access to private repositories. Together, these vulnerabilities allow extraction of the contents of any repositories from Radicle nodes.
  • A vulnerability in the Linux kernel, caused by accessing already freed memory (use-after-free) due to a race condition in the espintcp module used for encapsulating the ESP (Encapsulating Security Payload) protocol in TCP (ESP-in-TCP, RFC 8229). The issue was fixed in the kernel in February before the release of 7.0. Just a few days ago, a working exploit was created for this vulnerability that allows code execution with root privileges on the system. The exploit's functionality was demonstrated in CentOS Stream 9 and Ubuntu 26.04 LTS.
  • A critical vulnerability (CVE-2026-87902) in the WordPress content management system that allows an unauthenticated visitor to execute PHP code on the server through manipulation of page templates, provided a pearcmd.php file is present on the server (which is available in the official docker image and in the cPanel configuration by default). This problem also manifests in the ClassicPress fork. The vulnerability is actively exploited by attackers to take control of websites. A fix has been released for 25 branches of WordPress, ranging from 7.1.2 to 4.7.37.
  • Seven vulnerabilities in OpenVPN, including issues caused by double free (CVE-2026-84471), incorrect escaping of special characters during command interpreter execution (CVE-2026-84256), and one-byte buffer overflow while parsing DHCP options (CVE-2026-81738). These issues have been addressed in the OpenVPN release 2.6.23.
  • 8 vulnerabilities in the NTFS-3G package that could potentially allow code execution with root privileges when processing specially crafted partitions or disk images with the NTFS filesystem. All vulnerabilities are caused by buffer overflows. The issues have been fixed in NTFS-3G version 2026.9.18.
  • A vulnerability in FreeRDP that allows establishing an RDP connection without authentication. The issue was resolved in FreeRDP release 3.31.0. proxy server The issue was resolved in FreeRDP release 3.31.0.
  • A vulnerability (CVE-2026-87766) in the Bubblewrap toolkit for setting up isolated environments that allows writing files outside the sandbox environment during container setup by manipulating symbolic links.
  • An exploit has been published for a vulnerability in the CUPS print server, allowing a local user to gain root privileges on the system by overwriting the file /etc/cups/cups-files.conf (by specifying this file as a printer URI) and replacing the cups-exec call. A CUPS update has not been released yet.
  • Access to already freed memory (CVE-2026-42007) in the Dovecot IMAP server, allowing an authenticated user to achieve code execution on the server by using a specially crafted Sieve script. The vulnerability has been fixed in Dovecot release 2.4.5.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster