Sceawere
Vulnerability Detail
CVE-2026-96279UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Flatpak OCI Arbitrary File Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 12h ago
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- Attack Type
- Improper Link Resolution Before File Access ('Link Following')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide installs running as root, this includes sensitive files such as /etc/shadow.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-27T20:16:53.043Z",
"pubdate": "2026-09-27T20:16:53.043Z",
"executiveSummary": "This vulnerability involves an improper validation flaw within the Flatpak OCI remote extraction process, allowing for arbitrary file disclosure on the host system. By leveraging malicious OCI registry artifacts, an attacker can coerce the extraction process into creating hardlinks to sensitive host filesystem objects within the application's installation directory.\nThe vulnerability is characterized as an arbitrary file read/disclosure issue. If an attacker successfully tricks a user into installing or updating a Flatpak application from a compromised or malicious OCI registry, they can gain unauthorized read access to arbitrary files residing on the host. When the installation process is executed with administrative privileges—such as system-wide Flatpak installations—the scope of exposed data extends to critical system credentials and sensitive configurations, including /etc/shadow.\nThe risk implication is critical, as it facilitates unauthorized information disclosure, potentially leading to full system compromise depending on the sensitive data exfiltrated. Exploitation requires the victim to interact with a malicious OCI remote, making this a supply-chain style attack vector. There are no authentication requirements for the attacker beyond hosting a malicious registry, and the vulnerability exploits the implicit trust placed in the OCI transport mechanism during the Flatpak manifest parsing and extraction phase.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient sanitization and path validation mechanisms during the extraction of OCI image layers by Flatpak. When Flatpak processes an OCI-compliant container image for installation, it performs file extraction operations that fail to adequately verify or restrict the creation of filesystem hardlinks.\nThe attack flow begins when a user initiates a Flatpak installation or update pointing to a malicious OCI remote. The attacker-controlled registry provides an image layer containing a crafted archive entry that instructs the extraction process to create a hardlink pointing to a sensitive target on the host filesystem (e.g., /etc/shadow). Because the extraction logic does not enforce a chroot-like boundary or validate the source/target relationship of links, the Flatpak daemon creates an entry within the application's local installation directory that is effectively a link to the restricted file.\nOnce the file is hardlinked into the application's directory, the contents of the target file become readable to the user running the Flatpak command. In scenarios where Flatpak is performing a system-wide installation (typically executing as root), the daemon maintains high privileges during the extraction phase. The creation of the hardlink bypasses standard filesystem permissions because the process operating as root has the authority to link these files. After the installation, the attacker can access the exposed content by simply reading the linked file within the application directory structure, provided they have access to the destination path.\nThe vulnerable component is the OCI transport and extraction module within the Flatpak binary. The exploitation does not require prior authentication to the target system, relying instead on the victim's action of fetching resources from an untrusted registry. The payload behavior is strictly limited to file disclosure; however, the impact is severe due to the ability to target arbitrary files. Post-exploitation, the attacker possesses the contents of the target file, which may contain sensitive configuration data, cryptographic material, or authentication hashes."
}