Input validation error in Flatpak - CVE-2026-97027
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper validation of exported vendor-extension keys in Flatpak's Desktop Entry and D-Bus Service file export handling when exporting application metadata. A local user can include arbitrary keys in exported Desktop Entry or D-Bus Service files to cause a denial of service.