VDB
GCVE-110-AUR-2026-000287
GCVE-110-AUR-2026-000287
Advisory Published
The Arch User Repository (AUR) package `cubieboard-livesuit` was identified as malicious during the June 2026 AUR supply-chain compromise, in which an attacker pushed backdoored PKGBUILDs to roughly 1,900 packages. Building or installing the affected package executed attacker-controlled code. The malicious revision has since been removed from the AUR. Upstream package description: "LiveSuit is a tool to flash Images to the NAND of Allwinner devices, such as Cubieboard1, Cubieboard2, and Cubietruck. This package use the ZIP that comes from official Cubieboard download page.".
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| aur | cubieboard-livesuit | * (affected) | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.