{"id":183486,"date":"2026-09-27T10:53:30","date_gmt":"2026-09-27T08:53:30","guid":{"rendered":"https:\/\/prohoster.info\/blog\/news\/uyazvimosti-v-lxd-incus-flatpak-gitlab-radicle-yadre-linux-wordpress-openvpn-ntfs-3g-freerdp-cups-i-dovecot"},"modified":"2026-09-27T10:53:35","modified_gmt":"2026-09-27T08:53:35","slug":"vulnerabilities-in-lxd-incus-flatpak-gitlab-radicle-the-linux-kernel-wordpress-openvpn-ntfs-3g-freerdp-cups-and-dovecot","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/vulnerabilities-in-lxd-incus-flatpak-gitlab-radicle-the-linux-kernel-wordpress-openvpn-ntfs-3g-freerdp-cups-and-dovecot","title":{"rendered":"Vulnerabilities in LXD, Incus, Flatpak, GitLab, Radicle, the Linux kernel, WordPress, OpenVPN, NTFS-3G, FreeRDP, CUPS, and Dovecot","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Several recently discovered vulnerabilities allow for root access within the system or achieve remote code execution.    <\/p>\n<ul>\n<li class=\"l\"> 7 vulnerabilities in the LXD container management system and 11 vulnerabilities in the Incus fork. Several vulnerabilities, marked as critical, allow local unprivileged users to modify any files on the system or execute their code with root privileges. The vulnerabilities have been fixed in LXD versions 6.9, 5.21.8, 5.0.10, and 4.0.14, as well as in Incus 7.5.1. The issues were caused by incorrect handling of file paths, problems with symbolic links, and a lack of input validation in the code for migrating and backing up isolated environments or loading system images:\n<ul>\n<li class=\"l\"> CVE-2026-85526 \u2014 arbitrary file overwrite in the system when processing a backup containing a path in subvolumes[].path to a mount point like \u00ab..\\\/..\\\/..\\\/..\\\/etc\\\/cron.d\u00bb.\n<li class=\"l\"> CVE-2026-85185 \u2014 arbitrary file creation and deletion through the use of paths with \u00ab..\\\/\u00bb in the names of btrfs subvolumes.\n<li class=\"l\"> CVE-2026-87799 \u2014 writing to an arbitrary file in the system through the substitution of symbolic links during migration. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/vps\/\"   title=\"of virtual machines\" data-wpil-keyword-link=\"linked\">of virtual machines<\/a>.\n<li class=\"l\"> CVE-2026-87798 \u2014 escaping the base directory of the virtual machine during recursive file transfers.\n<li class=\"l\"> CVE-2026-86334 \u2014 escaping the base directory when exporting an image from an external source. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/dts-los-angeles\/\"   title=\"server\" data-wpil-keyword-link=\"linked\">server<\/a>.\n<li class=\"l\"> CVE-2026-86335 \u2014 access to private virtual machine images of other users.\n<li class=\"l\"> CVE-2026-97335 \u2014 bypassing access restrictions to projects.  <\/ul>\n<li class=\"l\"> Vulnerabilities in the Flatpak self-contained packages system. Issues have been fixed in Flatpak version 1.18.1. Among the most dangerous vulnerabilities are:\n<ul>\n<li class=\"l\"> CVE-2026-90616 \u2014 using symbolic links to bypass sandbox isolation and gain full access to the host file system;\n<li class=\"l\"> Privilege escalation to root user via symbolic link substitution (CVE not assigned);\n<li class=\"l\"> CVE-2026-9627 \u2014 writing files with root privileges through path manipulation;\n<li class=\"l\"> CVE-2026-96275 \u2014 writing files with root privileges through manipulation of symbolic links;\n<li class=\"l\"> CVE-2026-96276 \u2014 writing files with root privileges through substitution of \u00ab..\\\/\u00bb in file paths when executing the command \u00abflatpak build-init\u00bb;\n<li class=\"l\"> CVE-2026-96279 \u2014 reading arbitrary files in the main system by creating a hard link when extracting an OCI archive.\n<li class=\"l\"> CVE-2026-92162 \u2014 accessing files outside the base directory through substitution of \u00ab..\\\/\u00bb in DeployAppstream parameters.\n<li class=\"l\"> CVE-2026-96280 \u2014 buffer overflow in the OCI delta update handler on 32-bit systems.  <\/ul>\n<li class=\"l\"> Two critical vulnerabilities in the collaboration platform GitLab that allow a remote authenticated user to execute their code on <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/dts-newyork\/\"   title=\"server\" data-wpil-keyword-link=\"linked\">server<\/a> by injecting a specially crafted regular expression into the CI\/CD settings. The vulnerabilities reside in the regular expression parser and are caused by double free (CVE-2026-89078) and integer overflow (CVE-2026-93577). These issues have been addressed in releases 19.4.1, 19.3.3, and 19.2.7.\n<li class=\"l\"> Two critical vulnerabilities in the network protocol used on nodes of the decentralized collaboration platform Radicle. The first vulnerability allows the viewing of data exchanged by nodes through traffic monitoring. The second vulnerability enables spoofing of the node identifier to gain access to private repositories. Together, these vulnerabilities allow extraction of the contents of any repositories from Radicle nodes.\n<li class=\"l\"> A vulnerability in the Linux kernel, caused by accessing already freed memory (use-after-free) due to a race condition in the espintcp module used for encapsulating the ESP (Encapsulating Security Payload) protocol in TCP (ESP-in-TCP, RFC 8229). The issue was fixed in the kernel in February before the release of 7.0. Just a few days ago, a working exploit was created for this vulnerability that allows code execution with root privileges on the system. The exploit's functionality was demonstrated in CentOS Stream 9 and Ubuntu 26.04 LTS.\n<li class=\"l\"> A critical vulnerability (CVE-2026-87902) in the WordPress content management system that allows an unauthenticated visitor to execute PHP code on the server through manipulation of page templates, provided a pearcmd.php file is present on the server (which is available in the official docker image and in the cPanel configuration by default). This problem also manifests in the ClassicPress fork. The vulnerability is actively exploited by attackers to take control of websites. A fix has been released for 25 branches of WordPress, ranging from 7.1.2 to 4.7.37.\n<li class=\"l\"> Seven vulnerabilities in OpenVPN, including issues caused by double free (CVE-2026-84471), incorrect escaping of special characters during command interpreter execution (CVE-2026-84256), and one-byte buffer overflow while parsing DHCP options (CVE-2026-81738). These issues have been addressed in the OpenVPN release 2.6.23.\n<li class=\"l\"> 8 vulnerabilities in the NTFS-3G package that could potentially allow code execution with root privileges when processing specially crafted partitions or disk images with the NTFS filesystem. All vulnerabilities are caused by buffer overflows. The issues have been fixed in NTFS-3G version 2026.9.18.\n<li class=\"l\"> A vulnerability in FreeRDP that allows establishing an RDP connection without authentication. The issue was resolved in FreeRDP release 3.31.0. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/dts-prohoster\/\"   title=\"proxy server\" data-wpil-keyword-link=\"linked\">proxy server<\/a> The issue was resolved in FreeRDP release 3.31.0.\n<li class=\"l\"> A vulnerability (CVE-2026-87766) in the Bubblewrap toolkit for setting up isolated environments that allows writing files outside the sandbox environment during container setup by manipulating symbolic links.\n<li class=\"l\"> An exploit has been published for a vulnerability in the CUPS print server, allowing a local user to gain root privileges on the system by overwriting the file \/etc\/cups\/cups-files.conf (by specifying this file as a printer URI) and replacing the cups-exec call. A CUPS update has not been released yet.\n<li class=\"l\"> Access to already freed memory (CVE-2026-42007) in the Dovecot IMAP server, allowing an authenticated user to achieve code execution on the server by using a specially crafted Sieve script. The vulnerability has been fixed in Dovecot release 2.4.5.      <\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=66350\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0438\u043b\u0438 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430. 7 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430\u043c\u0438 LXD \u0438 11 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0444\u043e\u0440\u043a\u0435 Incus. \u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u043c\u0435\u0447\u0435\u043d\u043d\u044b\u0435 \u043a\u0430\u043a \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0435, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u044b\u043c \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u043c \u0438\u0437\u043c\u0435\u043d\u0438\u0442\u044c \u043b\u044e\u0431\u044b\u0435 \u0444\u0430\u0439\u043b\u044b \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0438\u043b\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u0445 LXD 6.9, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":10,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-183486","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0438\u043b\u0438 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Alexander Kovalev\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/vulnerabilities-in-lxd-incus-flatpak-gitlab-radicle-the-linux-kernel-wordpress-openvpn-ntfs-3g-freerdp-cups-and-dovecot\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 LXD, Incus, Flatpak, GitLab, Radicle, \u044f\u0434\u0440\u0435 Linux, WordPress, OpenVPN, NTFS-3G, FreeRDP, CUPS \u0438 Dovecot | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0438\u043b\u0438 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/vulnerabilities-in-lxd-incus-flatpak-gitlab-radicle-the-linux-kernel-wordpress-openvpn-ntfs-3g-freerdp-cups-and-dovecot\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-27T08:53:30+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-27T08:53:35+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilities in LXD, Incus, Flatpak, GitLab, Radicle, Linux kernel, WordPress, OpenVPN, NTFS-3G, FreeRDP, CUPS, and Dovecot | ProHoster","description":"Several recently discovered vulnerabilities allow for root access within the system or achieve remote code execution.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/vulnerabilities-in-lxd-incus-flatpak-gitlab-radicle-the-linux-kernel-wordpress-openvpn-ntfs-3g-freerdp-cups-and-dovecot","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 LXD, Incus, Flatpak, GitLab, Radicle, \u044f\u0434\u0440\u0435 Linux, WordPress, OpenVPN, NTFS-3G, FreeRDP, CUPS \u0438 Dovecot | ProHoster","og:description":"\u041d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u043e\u043f\u0430\u0441\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0445 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0438\u043b\u0438 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/vulnerabilities-in-lxd-incus-flatpak-gitlab-radicle-the-linux-kernel-wordpress-openvpn-ntfs-3g-freerdp-cups-and-dovecot","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-09-27T08:53:30+00:00","article:modified_time":"2026-09-27T08:53:35+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/183486","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=183486"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/183486\/revisions"}],"predecessor-version":[{"id":183487,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/183486\/revisions\/183487"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=183486"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=183486"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=183486"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}