Flatpak Host File Disclosure via Hardlinking from Malicious OCI Registry
CVE-2026-96279 Published on September 27, 2026
Flatpak: flatpak: path traversal issue in oci archive extraction via hardlinks
A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide installs running as root, this includes sensitive files such as /etc/shadow.
Vulnerability Analysis
CVE-2026-96279 can be exploited with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an insecure temporary file Vulnerability?
The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVE-2026-96279 has been classified to as an insecure temporary file vulnerability or weakness.
Products Associated with CVE-2026-96279
Want to know whenever a new CVE is published for Red Hat Enterprise Linux (RHEL)? stack.watch will email you.