PatchSiren cyber security CVE debrief
CVE-2026-104982 Linux Mint CVE debrief
A path traversal vulnerability was found in Linux Mint Xreader up to version 4.6.5 in the EPUB file handler. The issue is caused by a flaw in the `setup_document_content_list` and `g_strdup_printf` functions in the `backend/epub/epub-document.c` file. This vulnerability allows remote attackers to perform path traversal attacks. The exploit has been published and may be used. Upgrading to version 4.6.6 addresses this issue.
- Vendor
- Linux Mint
- Product
- Xreader
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for Linux Mint Xreader deployments should assess exposure and prioritize upgrading to version 4.6.6. This includes operators, platform administrators, vulnerability management teams, and security teams who oversee Linux Mint Xreader installations. They should review the vulnerability details, assess the potential impact on their systems, and plan for the necessary upgrades or mitigations. Additionally, they should verify patch and 4.
Why it matters
Defenders should prioritize upgrading to version 4.6.6 to address this path traversal vulnerability in Linux Mint Xreader up to version 4.6.5. The exploit has been published, but there is no information on in-the-wild exploitation. The CVSS score is 2.1, indicating a low severity vulnerability.
- Path traversal attacks may lead to unauthorized access to sensitive files
- Successful exploitation requires user interaction
- Verify patch application and monitor for potential exploitation attempts
- Remediation priority is low due to CVSS score of 2.1
Technical summary
The vulnerability is caused by a flaw in the `setup_document_content_list` and `g_strdup_printf` functions in the `backend/epub/epub-document.c` file of the Linux Mint Xreader up to version 4.6.5. This allows remote attackers to perform path traversal attacks. The issue arises when processing EPUB files, potentially leading to unauthorized access to sensitive files. Defenders should focus on upgrading to version 4.6.6 as a primary mitigation strategy. The CVE record and source metadata indicate a path traversal vulnerability in Linux Mint Xreader up to version 4.6.5. The exploit has been published, but there is no information on in-the-wild exploitation.
Defensive priority
Defenders should prioritize upgrading to version 4.6.6 to address this vulnerability.
Recommended defensive actions
- Upgrade to version 4.6.6
- Review and verify the patch
- Monitor for potential exploitation attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and source metadata indicate a path traversal vulnerability in Linux Mint Xreader up to version 4.6.5. The exploit has been published, but there is no information on in-the-wild exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104982 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104982
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104982 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104982
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://gist.github.com/rodtvs/63a34e7b20a9f97a1a7167a8a1db49c2
-
Source reference
Unverified legacy reference
URL: https://github.com/linuxmint/xreader/commit/a5aecea074e8564b7a22f1ce054b31ec862974b7
-
Source reference
Unverified legacy reference
URL: https://github.com/linuxmint/xreader/issues/713
-
Source reference
Unverified legacy reference
URL: https://github.com/linuxmint/xreader/releases/tag/4.6.6
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-104982
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/964347
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413198
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413198/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.