CVE-2026-10037
Public on 2026-07-08
Modified on 2026-08-26
Description
A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | java-1.7.0-openjdk | No Fix Planned | ||
| Amazon Linux 2 - Corretto8 Extra | java-1.8.0-amazon-corretto | Not Affected | ||
| Amazon Linux 2023 | java-1.8.0-amazon-corretto | Not Affected | ||
| Amazon Linux 2 - Core | java-1.8.0-openjdk | Not Affected | ||
| Amazon Linux 2 - Core | java-11-amazon-corretto | Not Affected | ||
| Amazon Linux 2023 | java-11-amazon-corretto | Not Affected | ||
| Amazon Linux 2 - Core | java-17-amazon-corretto | Not Affected | ||
| Amazon Linux 2023 | java-17-amazon-corretto | Not Affected | ||
| Amazon Linux 2023 | java-21-amazon-corretto | Not Affected | ||
| Amazon Linux 2023 | java-22-amazon-corretto | No Fix Planned | ||
| Amazon Linux 2023 | java-23-amazon-corretto | No Fix Planned | ||
| Amazon Linux 2023 | java-24-amazon-corretto | Not Affected | ||
| Amazon Linux 2023 | java-25-amazon-corretto | Not Affected | ||
| Amazon Linux 2023 | java-26-amazon-corretto | Not Affected | ||
| Amazon Linux 2 - Core | mailcap | Not Affected | ||
| Amazon Linux 2023 | mailcap | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 8.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |