Skip to content
Critical Vulnerability in Ubuntu 22.04 LTS Zutty Allows Arbitrary Command Execution

Critical Vulnerability in Ubuntu 22.04 LTS Zutty Allows Arbitrary Command Execution

First seen 6 Mar 2026, 08:11 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

A security vulnerability has been identified in Zutty, an X terminal emulator included in Ubuntu 22.04 LTS. Discovered by Carter Sande, the flaw allows attackers to execute arbitrary commands by exploiting improper input handling on DECRQSS. Users of Ubuntu and its derivatives are advised to apply patches to mitigate this risk.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

Timeline

2022-09-20
CVE-2022-41138 published
2026-03-05
Ubuntu announces USN-8078-1 for Zutty vulnerability
2026-03-06
Linuxsecurity reports on Zutty vulnerability

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2022-41138 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed