ZeroHour

Search: “sandbox escape”

3 stories

USN-8732-1: Minetest vulnerability

Ubuntu issued USN-8732-1 fixing a Minetest LuaJIT sandbox escape that let malicious mods execute arbitrary code on servers.

Ubuntu Security Notice USN-8732-1 addresses a flaw in Minetest where the Lua sandbox environment was not properly sanitized when using LuaJIT. A malicious mod could escape the sandbox, execute arbitrary code, and gain full file system access on the server. Administrators should update to the patched packages.

Ubuntu Security Notices · 9d agoAdvisory

USN-8741-1: Flatpak vulnerabilities

Ubuntu patched two Flatpak flaws, including a sandbox escape via app-controlled symlinks allowing host code execution (CVE-2026-34078).

Ubuntu security notice USN-8741-1 fixes two Flatpak vulnerabilities in Ubuntu 20.04 LTS, 22.04 LTS, and 24.04 LTS. CVE-2026-34078 stems from improper path validation in sandbox-expose options, letting a malicious or compromised Flatpak app use app-controlled symlinks to access arbitrary host files and gain code execution in the host context. CVE-2026-34079 involves improper path validation when removing outdated ld.so cache files, allowing a compromised app to delete arbitrary files on the host.

Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks

Google's September 2026 Android bulletin fixes over 30 critical flaws, including no-interaction system RCEs, a TIPC kernel RCE and a Qualcomm closed-source bug

Google's Android Security Bulletin for September 2026 (patch levels 2026-09-01 and 2026-09-05) fixes numerous critical System remote code execution flaws, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919 and CVE-2026-49921, none requiring user interaction or additional privileges. It also addresses critical kernel issues including a TIPC RCE (CVE-2026-52993) and elevation-of-privilege flaws in NFC and protected KVM, plus a critical Qualcomm closed-source component flaw (CVE-2026-25289). Affected versions span Android 14 through 17; the 2026-09-05 patch level extends coverage to Android TV and chipset components, with high-severity fixes for Arm Mali, PowerVR, MediaTek, Unisoc and Qualcomm components.