Search CVE reports


Toggle filters

1 – 10 of 36 results


CVE-2026-97029

Medium priority
Needs evaluation

Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised...

1 affected package

flatpak

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flatpak Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-97027

Medium priority
Needs evaluation

Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, instead of validating against an allowlist. A malicious Flatpak app can...

1 affected package

flatpak

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flatpak Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-97026

Medium priority
Needs evaluation

Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used...

1 affected package

flatpak

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flatpak Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-97025

Medium priority
Needs evaluation

Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate...

1 affected package

flatpak

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flatpak Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-97024

Medium priority
Needs evaluation

A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be...

1 affected package

flatpak

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flatpak Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-97023

Medium priority
Needs evaluation

A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is...

1 affected package

flatpak

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flatpak Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-96808

Medium priority
Needs evaluation

In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged callers, validated file paths by rejecting literal .. components but did not prevent symlink traversal....

1 affected package

flatpak

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flatpak Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-96807

Medium priority
Needs evaluation

In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. The filenames and content are not attacker controlled,...

1 affected package

flatpak

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flatpak Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-96284

Medium priority
Needs evaluation

security update

1 affected package

flatpak

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flatpak Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-96283

Medium priority
Needs evaluation

security update

1 affected package

flatpak

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flatpak Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages