PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104982 Linux Mint CVE debrief

A path traversal vulnerability was found in Linux Mint Xreader up to version 4.6.5 in the EPUB file handler. The issue is caused by a flaw in the `setup_document_content_list` and `g_strdup_printf` functions in the `backend/epub/epub-document.c` file. This vulnerability allows remote attackers to perform path traversal attacks. The exploit has been published and may be used. Upgrading to version 4.6.6 addresses this issue.

Vendor
Linux Mint
Product
Xreader
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

Defenders responsible for Linux Mint Xreader deployments should assess exposure and prioritize upgrading to version 4.6.6. This includes operators, platform administrators, vulnerability management teams, and security teams who oversee Linux Mint Xreader installations. They should review the vulnerability details, assess the potential impact on their systems, and plan for the necessary upgrades or mitigations. Additionally, they should verify patch and 4.

Why it matters

Defenders should prioritize upgrading to version 4.6.6 to address this path traversal vulnerability in Linux Mint Xreader up to version 4.6.5. The exploit has been published, but there is no information on in-the-wild exploitation. The CVSS score is 2.1, indicating a low severity vulnerability.

  • Path traversal attacks may lead to unauthorized access to sensitive files
  • Successful exploitation requires user interaction
  • Verify patch application and monitor for potential exploitation attempts
  • Remediation priority is low due to CVSS score of 2.1

Technical summary

The vulnerability is caused by a flaw in the `setup_document_content_list` and `g_strdup_printf` functions in the `backend/epub/epub-document.c` file of the Linux Mint Xreader up to version 4.6.5. This allows remote attackers to perform path traversal attacks. The issue arises when processing EPUB files, potentially leading to unauthorized access to sensitive files. Defenders should focus on upgrading to version 4.6.6 as a primary mitigation strategy. The CVE record and source metadata indicate a path traversal vulnerability in Linux Mint Xreader up to version 4.6.5. The exploit has been published, but there is no information on in-the-wild exploitation.

Defensive priority

Defenders should prioritize upgrading to version 4.6.6 to address this vulnerability.

Recommended defensive actions

  • Upgrade to version 4.6.6
  • Review and verify the patch
  • Monitor for potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and source metadata indicate a path traversal vulnerability in Linux Mint Xreader up to version 4.6.5. The exploit has been published, but there is no information on in-the-wild exploitation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104982 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104982

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104982 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104982

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.