Sceawere
Vulnerability Detail
CVE-2026-96280UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Flatpak OCI Integer Truncation Overflow
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 11h ago
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- Attack Type
- Numeric Truncation Error
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-27T21:17:04.200Z",
"pubdate": "2026-09-27T21:17:04.200Z",
"executiveSummary": "A critical integer truncation vulnerability exists within the Flatpak OCI delta stream parser. The flaw arises from a type mismatch when handling 64-bit size values during memory allocation and I/O operations on 32-bit architectures.\nThis vulnerability allows an attacker who controls a malicious OCI registry to trigger a heap-based buffer overflow during the installation or update process of a Flatpak package.\nThe successful exploitation of this flaw can lead to memory corruption, potentially resulting in arbitrary code execution within the context of the user running the Flatpak utility.\nThe risk is specifically localized to 32-bit systems where gsize is limited to 32 bits, contrasting with the 64-bit variables used for input validation. This represents a significant security risk for systems relying on Flatpak for package management, as the exploit is triggered automatically upon interaction with a compromised or malicious registry.\nThe vulnerability does not require authentication to the target system but necessitates the target to pull data from a controlled OCI source.",
"technicalDetails": "The root cause of this vulnerability is an improper type conversion during the parsing of delta streams in the OCI (Open Container Initiative) component of Flatpak. The parser correctly parses delta stream segment sizes as guint64; however, these values are subsequently passed to GLib I/O and memory allocation functions that expect gsize, which is a 32-bit type on 32-bit architectures.\nDuring the conversion from guint64 to gsize, the value is truncated. For instance, an attacker can specify a 64-bit size that, when truncated to 32 bits, results in a small value suitable for an allocation function. This results in the system allocating a buffer significantly smaller than the actual amount of data expected for the transfer.\nThe attack flow initiates when the Flatpak utility connects to an OCI registry to perform an installation or update. If the registry provides a crafted delta stream, the parser reads the large 64-bit size value. When the software proceeds to write the stream data into the undersized heap buffer, it utilizes the original 64-bit size. This mismatch forces the I/O operation to copy an amount of data that exceeds the boundaries of the allocated heap memory.\nThis behavior results in a heap-based buffer overflow. Because this occurs during the execution of Flatpak, the overflow can corrupt adjacent heap structures or overwrite critical data pointers. An attacker can leverage this memory corruption to control the application's execution flow, potentially leading to arbitrary code execution (ACE).\nOn 32-bit architectures, the address space and heap management become particularly susceptible to such overflows. The vulnerability effectively bypasses size checks that are performed in 64-bit space but are invalidated by the narrowing conversion to gsize before the actual buffer reservation occurs. This requires no prior authentication on the victim machine, as the exploit is delivered as part of the standard container metadata and layer stream retrieval process inherent to the OCI specification implementation in Flatpak."
}