SB20260928313 - Multiple vulnerabilities in Flatpak



SB20260928313 - Multiple vulnerabilities in Flatpak

Published: September 28, 2026

Security Bulletin ID SB20260928313
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 6
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 33% Low 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 6 vulnerabilities.


1) Improper isolation or compartmentalization (CVE-ID: CVE-2026-97029)

CWE-ID: CWE-653 - Improper isolation or compartmentalization

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper isolation or compartmentalization in Flatpak process ID namespace separation when a sandboxed app signals its current process group. A remote user can call kill(0, signal) or killpg(0, signal) to cause a denial of service.


2) Creation of Temporary File With Insecure Permissions (CVE-ID: CVE-2026-97025)

CWE-ID: CWE-378 - Creation of Temporary File With Insecure Permissions

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose OCI authentication tokens.

The vulnerability exists due to insecure file permissions in the OCI token cache path when downloading apps or runtimes from an authenticated OCI repository. A local user can read the token file to disclose OCI authentication tokens.

The issue is relevant to apps, runtimes, or extensions downloaded from OCI repositories.


3) Path traversal (CVE-ID: CVE-2026-97024)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause data loss and loss of access to the system.

The vulnerability exists due to path traversal in files/etc handling in deploy directories when upgrading a malicious Flatpak app. A remote attacker can supply a malicious Flatpak app containing crafted files to overwrite system files and cause data loss and loss of access to the system.

User interaction is required to upgrade the malicious app.


4) Path traversal (CVE-ID: CVE-2026-97023)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to delete arbitrary files outside the deployment directory.

The vulnerability exists due to path traversal in the export/bin handling in deploy directories when upgrading a malicious Flatpak app. A remote attacker can supply a malicious Flatpak app with crafted paths to delete arbitrary files outside the deployment directory.

User interaction is required to upgrade the malicious app. For system-wide installations, file deletion is performed as root.


5) Creation of Temporary File With Insecure Permissions (CVE-ID: CVE-2026-97026)

CWE-ID: CWE-378 - Creation of Temporary File With Insecure Permissions

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to insecure temporary directory permissions in temporary child repositories under the system-helper cache path when installing apps. A local user can modify the temporary directory to cause a denial of service.

Exploitation is limited to multi-user systems where the user's umask permits other users to write to the cache directory.


6) Input validation error (CVE-ID: CVE-2026-97027)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper validation of exported vendor-extension keys in Flatpak's Desktop Entry and D-Bus Service file export handling when exporting application metadata. A local user can include arbitrary keys in exported Desktop Entry or D-Bus Service files to cause a denial of service.


Remediation

Install update from vendor's website.