Back

HIGH

Sandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portal

Published Jul 8, 2026

Description

A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.

Affected products

Remediation

Red Hat statement

Red Hat products are not affected by this vulnerability. CVE-2026-10037 is a packaging defect specific to Debian/Ubuntu OpenJDK distributions: those distributions ship a desktop MIME handler that, via cautious-launcher and the mailcap application/x-java-archive association, can auto-execute a downloaded .jar file. The fix was delivered in the mailcap package (USN-8518-1), not in OpenJDK source code. Red Hat's OpenJDK RPMs ship only jconsole.desktop, which declares no MimeType and no .jar association, do not depend on or install mailcap, and register no application/x-java-archive handler. The vulnerable code path is therefore not present in any Red Hat OpenJDK build. This was independently confirmed downstream by the Hummingbird team, which resolved both trackers (HUM-3135, HUM-3136) as "Not a Bug / Vulnerable Code not Present."

Red Hat mitigation

No mitigation is required: Red Hat products are not affected. Red Hat's OpenJDK packages do not ship the .jar MIME handler, do not depend on the mailcap package, and register no application/x-java-archive association, so the vulnerable code path is not present. Users of Debian/Ubuntu OpenJDK should apply the upstream mailcap fix (USN-8518-1).

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Jul 8, 2026
Updated Jul 14, 2026
Reserved May 28, 2026
CISA Vulnrichment
Updated Jul 10, 2026
NVD
Status Awaiting Analysis
Modified Jul 14, 2026
Red Hat
Severity Important
Public date Jul 8, 2026