CVE-2026-96275

high
Assigned by CNA: redhat
Published 2026-09-23 · Modified 2026-09-23
CVSS v3
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4 NEW
not yet in upstream
VIR risk
8.8

Description

A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.

Predictions

Exploit likelihood
92%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-96275 NameCVE-2026-96275 DescriptionGHSA-fqx6-vh4p-42cg SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) ReferencesDSA-6432-1 Debian Bugs1144130 Vulnerable and fixed packages The table below lists information on source packages. Source PackageReleaseVersionStatus flatpak…

CVE-2026-96275

NameCVE-2026-96275
DescriptionGHSA-fqx6-vh4p-42cg
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6432-1
Debian Bugs1144130

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
flatpak (PTS)bookworm, bookworm (security)1.14.10-1~deb12u2vulnerable
trixie (security), trixie1.16.6-1~deb13u2fixed
forky1.18.2-1fixed
sid1.18.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
flatpaksourcetrixie1.16.6-1~deb13u2DSA-6432-1
flatpaksource(unstable)1.18.1-11144130

Notes

https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg
Fixed by: https://github.com/flatpak/flatpak/commit/c42326c74d63e550d874312be0c7a800cf5fc39f (1.18.1)
Fixed by: https://github.com/flatpak/flatpak/commit/12a30ecb422b1e1246cb2d9af60c14ef7b8f22a4 (1.18.1)
Fixed by: https://github.com/flatpak/flatpak/commit/eef9aaee0d84138b5b0e440f739bf9504757e5a4 (1.18.1)
Fixed by: https://github.com/flatpak/flatpak/commit/4266256cd47e2d9b35da59046bc03f2bd4de3a2a (1.18.1)
Fixed by: https://github.com/flatpak/flatpak/commit/e8050164eab924d496a42b44c7145fbecf213993 (1.18.1)
Fixed by: https://github.com/flatpak/flatpak/commit/fb8ae524738e0a0097a6d64bfcda71552174b7fb (branch flatpak-1.16.x)
Fixed by: https://github.com/flatpak/flatpak/commit/c0a109aa4f861f557aed60c42d0ee64d2c3a943c (branch flatpak-1.16.x)
Fixed by: https://github.com/flatpak/flatpak/commit/104c7a63bca482155ace642d59d4765f57f4ecaa (branch flatpak-1.16.x)
Fixed by: https://github.com/flatpak/flatpak/commit/c9b4b4946a7fc8d4a79a454a9d70faee5f7af820 (branch flatpak-1.16.x)
Fixed by: https://github.com/flatpak/flatpak/commit/de3decabfd2bc62a774698342d1a9e8ea98077d7 (branch flatpak-1.16.x)
Additional requirement: https://github.com/flatpak/flatpak/commit/3d43a0f5fa602cc3edc557d8ab835030140792b1 (branch flatpak-1.16.x)
Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cgFixed by: https://github.com/flatpak/flatpak/commit/c42326c74d63e550d874312be0c7a800cf5fc39f (1.18.1)Fixed by: https://github.com/flatpak/flatpak/commit/12a30ecb422b1e1246cb2d9af60c14ef7b8f22a4 (1.18.1)Fixed by: https://github.com/flatpak/flatpak/commit/eef9aaee0d84138b5b0e440f739bf9504757e5a4 (1.18.1)Fixed by: https://github.com/flatpak/flatpak/commit/4266256cd47e2d9b35da59046bc03f2bd4de3a2a (1.18.1)Fixed by: https://github.com/flatpak/flatpak/commit/e8050164eab924d496a42b44c7145fbecf213993 (1.18.1)Fixed by: https://github.com/flatpak/flatpak/commit/fb8ae524738e0a0097a6d64bfcda71552174b7fb (branch flatpak-1.16.x)Fixed by: https://github.com/flatpak/flatpak/commit/c0a109aa4f861f557aed60c42d0ee64d2c3a943c (branch flatpak-1.16.x)Fixed by: https://github.com/flatpak/flatpak/commit/104c7a63bca482155ace642d59d4765f57f4ecaa (branch flatpak-1.16.x)Fixed by: https://github.com/flatpak/flatpak/commit/c9b4b4946a7fc8d4a79a454a9d70faee5f7af820 (branch flatpak-1.16.x)Fixed by: https://github.com/flatpak/flatpak/commit/de3decabfd2bc62a774698342d1a9e8ea98077d7 (branch flatpak-1.16.x)Additional requirement: https://github.com/flatpak/flatpak/commit/3d43a0f5fa602cc3edc557d8ab835030140792b1 (branch flatpak-1.16.x)Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)

OS impact

debian Debian Mixed 4 releases
VersionStatusFixed in
trixie Fixed 1.16.6-1~deb13u2
sid Fixed 1.18.1-1
forky Fixed 1.18.1-1
bookworm Affected

References

CWEs

CWE-22

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.