High [CVE-2026-96275] Flatpak: flatpak: arbitrary write access as root via extra-data extraction
This high-severity Red Hat Linux advisory covers CVE-2026-96275 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root.
Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal. Red Hat estimates the CVSSv3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.
Exploitation requires a user or administrator to add or trust a malicious or compromised Flatpak repository and then install or update an application from it. The malicious content is served over the network (AV:N), and the attacker needs only control over the repository content (PR:N).
Meaningful user interaction is required, since a user/admin must actively configure the remote and initiate an install or update from it (UI:R).
Because this is an unconstrained, attacker-controlled write as root, it is treated as equivalent to full system compromise: an attacker can overwrite files such as SSH authorized_keys, systemd units, cron entries, or setuid binaries, yielding full loss of confidentiality, integrity, and availability (C:H/I:H/A:H).
Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-22.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
Mitigation checklist
- Avoid installing Flatpak extensions from non-trusted sources.
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.