CVE-2026-77113: Path Traversal Vulnerability in apport-unpack
Published Aug 20, 2026
·Updated
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.
Affected Software
1 affected component
Canonical apport-unpack<2.36.0, >2.34.2<=2.36.0, >2.28.4<=2.34.2
Event History
Aug 20, 2026
CVE Published
via MITRE·10:32 PM
Data Sourced
via MITRE·10:32 PM
DescriptionWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker needs to supply a crash report file containing attacker-controlled key names and have it processed by apport-unpack. Exploitation creates or overwrites files with the privileges of the user running apport-unpack.
2
Which versions are affected?
The issue affects Canonical Apport versions before 2.36.0, 2.34.2, and 2.28.4.