SB20260928313 - Multiple vulnerabilities in Flatpak
Published: September 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Improper isolation or compartmentalization (CVE-ID: CVE-2026-97029)
CWE-ID: CWE-653 - Improper isolation or compartmentalization
CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper isolation or compartmentalization in Flatpak process ID namespace separation when a sandboxed app signals its current process group. A remote user can call kill(0, signal) or killpg(0, signal) to cause a denial of service.
2) Creation of Temporary File With Insecure Permissions (CVE-ID: CVE-2026-97025)
CWE-ID: CWE-378 - Creation of Temporary File With Insecure Permissions
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose OCI authentication tokens.
The vulnerability exists due to insecure file permissions in the OCI token cache path when downloading apps or runtimes from an authenticated OCI repository. A local user can read the token file to disclose OCI authentication tokens.
The issue is relevant to apps, runtimes, or extensions downloaded from OCI repositories.
3) Path traversal (CVE-ID: CVE-2026-97024)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause data loss and loss of access to the system.
The vulnerability exists due to path traversal in files/etc handling in deploy directories when upgrading a malicious Flatpak app. A remote attacker can supply a malicious Flatpak app containing crafted files to overwrite system files and cause data loss and loss of access to the system.
User interaction is required to upgrade the malicious app.
4) Path traversal (CVE-ID: CVE-2026-97023)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to delete arbitrary files outside the deployment directory.
The vulnerability exists due to path traversal in the export/bin handling in deploy directories when upgrading a malicious Flatpak app. A remote attacker can supply a malicious Flatpak app with crafted paths to delete arbitrary files outside the deployment directory.
User interaction is required to upgrade the malicious app. For system-wide installations, file deletion is performed as root.
5) Creation of Temporary File With Insecure Permissions (CVE-ID: CVE-2026-97026)
CWE-ID: CWE-378 - Creation of Temporary File With Insecure Permissions
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to insecure temporary directory permissions in temporary child repositories under the system-helper cache path when installing apps. A local user can modify the temporary directory to cause a denial of service.
Exploitation is limited to multi-user systems where the user's umask permits other users to write to the cache directory.
6) Input validation error (CVE-ID: CVE-2026-97027)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper validation of exported vendor-extension keys in Flatpak's Desktop Entry and D-Bus Service file export handling when exporting application metadata. A local user can include arbitrary keys in exported Desktop Entry or D-Bus Service files to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://github.com/flatpak/flatpak/security/advisories/GHSA-f3p8-vr7v-gxf2
- https://github.com/flatpak/flatpak/commit/a3cf27b5d6f365777259bd26ffa0d369c5ed7874
- https://github.com/flatpak/flatpak/security/advisories/GHSA-7rvf-rqr3-43j4
- https://github.com/flatpak/flatpak/commit/f911bbf080e33b2b85c9dd6ea0a59898f969497c
- https://github.com/flatpak/flatpak/security/advisories/GHSA-8xgq-v545-vgvf
- https://github.com/flatpak/flatpak/commit/cc3ab6ab45b9cbca5a360608c51eb336a749d0e8
- https://github.com/flatpak/flatpak/security/advisories/GHSA-5p67-xh8x-rq54
- https://github.com/flatpak/flatpak/commit/40f1265c26fed576235b7a8748371e274b44de1c
- https://github.com/flatpak/flatpak/security/advisories/GHSA-r9w3-qx54-qvc8
- https://github.com/flatpak/flatpak/commit/011dfae2f76d27d7e148c575dca5309a3cb4c852
- https://github.com/flatpak/flatpak/security/advisories/GHSA-v64f-hrwr-j4vh
- https://github.com/flatpak/flatpak/commit/33931025ff74f4db7b09f0ad331e76f9fd9ab99e