GLSA-202608-12 : Portage: Multiple Vulnerabilities

high Nessus Plugin ID 335893

Description

The remote host is affected by the vulnerability described in GLSA-202608-12 (Portage: Multiple Vulnerabilities)

Multiple vulnerabilities have been discovered in Portage. Please review the bugs referenced below for details.

The first bug (bug 978478) allows a malicious ebuild (including a build system it uses indirectly) to write outside of the work directory. While malicious artifacts could be installed by a package itself, this is still unexpected if one only ran the configure phrase during development.

The second bug (bug 979026) is regarding insufficient sandboxing in global scope. Untrusted ebuilds, even if not emerged, may have the opportunity to run code in global scope depending on whether the repository has metadata available. Additional sandboxing has been added.

Tenable has extracted the preceding description block directly from the Gentoo Linux security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

All Portage users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot
--verbose >=sys-apps/portage-3.0.81.2 In general, we recommend users add external repositories with caution. If using external repositories, it is good practice to mask all packages by default from that repository, and unmask only needed packages.

See Also

https://bugs.gentoo.org/show_bug.cgi?id=978478

https://bugs.gentoo.org/show_bug.cgi?id=979026

https://security.gentoo.org/glsa/202608-12

Plugin Details

Severity: High

ID: 335893

File Name: gentoo_GLSA-202608-12.nasl

Version: 1.1

Type: Local

Published: 8/15/2026

Updated: 8/15/2026

Supported Sensors: Nessus

Vulnerability Information

CPE: cpe:/o:gentoo:linux, p-cpe:/a:gentoo:linux:portage

Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/15/2026

Vulnerability Publication Date: 8/15/2026