Heap-based buffer overflow in Flatpak - #VU141402
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the OCI delta stream parser when processing a crafted delta stream from a malicious OCI registry during installation or update. A remote attacker can supply a specially crafted OCI delta stream to execute arbitrary code.
Only 32-bit systems are practically exploitable. Flatpak remotes using the default OSTree transport are not affected.