CVE-2026-96279

medium
EUVD alias: EUVD-2026-88013
Assigned by CNA: redhat
Published 2026-09-27 · Modified 2026-09-28
CVSS v3
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS v4 NEW
—
not yet in upstream
VIR risk
6.5

Description

A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide installs running as root, this includes sensitive files such as /etc/shadow.

Predictions

Exploit likelihood
75%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-96279 NameCVE-2026-96279 DescriptionA malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide installs running as root, this includes sensitive files such as /etc/shadow. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec,…

CVE-2026-96279

NameCVE-2026-96279
DescriptionA malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide installs running as root, this includes sensitive files such as /etc/shadow.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1144130

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
flatpak (PTS)bookworm, bookworm (security)1.14.10-1~deb12u2fixed
trixie (security), trixie1.16.6-1~deb13u2fixed
forky, sid1.18.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
flatpaksourcebullseye(not affected)
flatpaksourcebookworm(not affected)
flatpaksourcetrixie(not affected)
flatpaksource(unstable)1.18.1-11144130

Notes

[trixie] - flatpak <not-affected> (Vulnerable code not present)
[bookworm] - flatpak <not-affected> (Vulnerable code not present)
[bullseye] - flatpak <not-affected> (Vulnerable code not present)
https://github.com/flatpak/flatpak/security/advisories/GHSA-9rww-v4mm-x4jg
Fixed by: https://github.com/flatpak/flatpak/commit/e6fa2f9b416ec382644694c8737dc8fbe7f07b89 (1.18.1)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[trixie] - flatpak <not-affected> (Vulnerable code not present)[bookworm] - flatpak <not-affected> (Vulnerable code not present)[bullseye] - flatpak <not-affected> (Vulnerable code not present)https://github.com/flatpak/flatpak/security/advisories/GHSA-9rww-v4mm-x4jgFixed by: https://github.com/flatpak/flatpak/commit/e6fa2f9b416ec382644694c8737dc8fbe7f07b89 (1.18.1)

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
— Affected —
debian Debian Fixed 4 releases
VersionStatusFixed in
trixie Fixed 0
sid Fixed 1.18.1-1
forky Fixed 1.18.1-1
bookworm Fixed 0

References

CWEs

CWE-59

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.