See how linux mint compares to other vendors in security performance
Hello,
The full reports for this vulnerability are available now:
Atril: https://github.com/mate-desktop/atril/security/advisories/GHSA-vgv2-m826-8f6f Evince: https://gitlab.gnome.org/GNOME/evince/-/workitems/2153
They contain a script for building malicious polyglot PDFs that are simultaneously both valid PDF files and also valid ELF binaries. When the user opens the PDF in the PDF viewer and clicks on a malicious link embedded in the PDF, the PDF abuses the command injection vulnerability to load itself as a GTK module using the --gtk-module command line flag. It can then execute arbitrary code via its library constructor. That flag was removed in GTK 4, which is why the vulnerability is much less serious for Papers than it is for Evince, Atril, and Xreader.
The provided script requires that the attacker predict the absolute path that the malicious PDF file will be saved to, generally /home/username/Downloads/attackerchosenname.pdf. However, in a follow-up comment on the Atril advisory, the reporter says that it's possible to modify the script to avoid the requirement to predict the file path.
My takeaway from this incident: AI tools are going to find a lot of vulnerabilities in the short term. A human inspecting this code should have been able to find the command injection vulnerability, but that requires time and effort, so nobody did. Running an AI and telling it to inspect the code is much easier. We're probably in for a rough time in the short term. But in the long term, we are going to be much more secure than we were before, so this is good.
Also, the AI is able to take an investigation much farther than a human would be willing to, crafting a creative working exploit when a human would have almost certainly just stopped after finding the vulnerability. This is unusual and dangerous, but the silver lining is it helps us appreciate the severity of the issue. It's often hard to assess how bad a vulnerability is. If not for the weaponized exploit, I would have thought this bug was not very scary and treated it as not a big deal. But the AI was clever and found a way to make it extremely scary! I don't know how much prompting the human reporter had to do to get this result.
Michael
Hi,
CVE-2026-46529 is a command injection vulnerability in Evince, Atril, and Xreader caused by missing quoting of shell-like input in evspawn() in ev-application.c. It is fixed by: • Evince 48.2 • Atril 1.28.4 and 1.26.3 • Xreader 4.6.4 and 3.6.7 The fixes for the issue are public in all three projects' git repos [1] [2] [3]. Distros, please start preparing updates immediately.
This bug also affects Papers [4], but it's probably not urgent to update Papers.
I'm doing a little experiment here: although the vulnerability itself is now public because those commits are public and because this is a public mailing list, I have nevertheless decided to keep the original issue reports and CVE details private until Thursday, May 21, because they contain a working exploit developed by a LLM. Perhaps that's arguably stretching the rules of this mailing list slightly, but hopefully this is OK since the flaw and the fix are both public.
I know this is not a standard embargo strategy. And the date is also very soon, leaving you not much time to react. I don't know if this was actually a good idea or not. Complaints welcome! My goal was to make it easy to prepare immediate distro updates without waiting for an embargo to end, while also not releasing the full exploit immediately. I expect people will surely figure out how to abuse this vulnerability shortly after I send this mail, but I'm hoping that attempts to do so will be initially less effective than what we'll release on Thursday.
[1] https://gitlab.gnome.org/GNOME/evince/-/commit/970c219e861a5fcc3e7b9e05bedf18cf0de39245 [2] https://github.com/mate-desktop/atril/commit/b989b7922a454ed81f8bb14786a958828513f576 [3] https://github.com/linuxmint/xreader/commit/50052eaa91c3c750c51c245799e3747495feeece [4] https://gitlab.gnome.org/GNOME/papers/-/commit/1b82bf627b4d8b414a57b55a9095e6d361799d6c
End of life: 4/30/2029
End of life: 4/30/2029
End of life: 4/30/2029
End of life: 4/30/2029
End of life: 4/30/2029
In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in checkconnection, dropdatareceivedcb, and Service.remove. A user can modify a service name in a ~/.linuxmint/mintUpload/services/service file.
Linux Mint Xreader CBT File Parsing Argument Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of CBT files. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22132.
Linux Mint Xreader EPUB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of EPUB files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-21897.
End of life: 4/30/2027
End of life: 4/30/2027
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CBT files. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the current user.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CBT files. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the current user.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EPUB files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EPUB files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user.
End of life: 1/1/2026
End of life: 1/1/2026
End of life: 4/30/2027
End of life: 4/30/2027
End of life: 4/30/2027
End of life: 4/30/2027
End of life: 4/30/2027
End of life: 4/30/2027
End of life: 7/1/2024
End of life: 7/1/2024
End of life: 4/30/2025
End of life: 4/30/2025
End of life: 4/30/2025