Sceawere

Vulnerability Detail

CVE-2026-96283UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Flatpak SystemHelper Unauthorized Pull Cancellation

Vulnerability Metadata

Severity
Low
Score / CVSS
3.3
Creation Date
10h ago
Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.3",
  "pubDate": "2026-09-27T22:17:06.557Z",
  "pubdate": "2026-09-27T22:17:06.557Z",
  "executiveSummary": "A vulnerability exists in the org.freedesktop.Flatpak.SystemHelper interface involving the improper management of pull operations. The vulnerability is categorized as an improper access control issue, allowing an unauthorized user to interact with and disrupt pull processes initiated by other users.\nThe flaw stems from insufficient authorization checks within the CancelPull method. By invoking this method on a pull identifier owned by another user, an attacker can manipulate the internal state of the Flatpak system helper. This results in the removal of the pull from internal tracking without actually terminating the underlying process.\nThe impact is a denial-of-service condition regarding the management of pull operations. Once the tracking is severed, the legitimate owner of the pull operation loses the ability to monitor, control, or cancel the ongoing process through standard interface methods. This can lead to resource exhaustion or persistent unwanted background activity. An attacker requires local access to the system to interact with the D-Bus interface. There is no evidence of remote exploitability, but the vulnerability compromises the integrity of multi-user environment management within the Flatpak subsystem.",
  "technicalDetails": "The vulnerability resides in the implementation of the org.freedesktop.Flatpak.SystemHelper D-Bus service, specifically within the CancelPull method. The D-Bus interface allows privileged operations related to application deployment and maintenance; however, the validation logic fails to verify that the requester possesses the necessary ownership permissions for the target pull ID.\nThe root cause is a lack of caller verification against the active pull session metadata. When the CancelPull method is invoked, the SystemHelper service does not validate if the UID of the calling process matches the UID of the user who initiated the pull operation. Instead, the service proceeds to execute the cancellation logic.\nThe exploitation flow is as follows: 1) A target user initiates a pull operation, which generates a specific pull ID tracked by the SystemHelper daemon. 2) An attacker, operating as a different local user, identifies or guesses the active pull ID. 3) The attacker issues a D-Bus call to org.freedesktop.Flatpak.SystemHelper.CancelPull, passing the target pull ID as an argument. 4) The daemon processes the request and removes the tracking record for the specified pull ID from its internal state management.\nThe technical consequence of this interaction is a desynchronization between the internal process management and the user-facing state. Because the daemon removes the tracking record without sending a termination signal (or equivalent SIGTERM/SIGKILL) to the underlying process threads, the pull operation continues to execute in the background, consuming network and system resources. Since the tracking is removed, the original owner of the pull operation can no longer see the operation in their client interface, making it impossible to terminate the process gracefully. This results in a permanent loss of control for the user over their own initiated tasks, effectively enabling a form of local resource-based denial-of-service and preventing the user from reclaiming bandwidth or disk I/O utilized by the orphaned pull process."
}
CVE-2026-96283: Flatpak SystemHelper Unauthorized Pull Cancellation (LOW Severity, CVSS: 3.3) | Sceawere