Sceawere
Vulnerability Detail
CVE-2026-96284UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Flatpak System Helper Symlink Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.5
- Creation Date
- 9h ago
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- Attack Type
- Improper Link Resolution Before File Access ('Link Following')
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.5",
"pubDate": "2026-09-27T23:17:01.130Z",
"pubdate": "2026-09-27T23:17:01.130Z",
"executiveSummary": "A file read vulnerability exists within the flatpak-system-helper component, specifically impacting environments configured with a system OCI (Open Container Initiative) repository.\nThe vulnerability originates from insecure file handling practices during the OCI image import process, where the helper fails to properly validate file paths.\nAn unprivileged local attacker can exploit this flaw to bypass filesystem permissions and gain read-access to sensitive system files.\nBy manipulating symlinks within an OCI image directory that is controlled by the user, an attacker can influence the helper process to follow these symlinks to unauthorized locations outside the intended import directory.\nThis represents a significant privilege escalation risk, as the flatpak-system-helper operates with elevated privileges, potentially exposing system configuration, credentials, or sensitive data to the attacker.\nSuccessful exploitation requires the attacker to have the ability to influence or place content into the OCI import directory utilized by the system helper. No network exposure is required, as the attack vector is purely local.",
"technicalDetails": "The vulnerability is rooted in an improper implementation of file path handling within the OCI image import logic of flatpak-system-helper. When the system helper processes an OCI image for installation, it traverses files contained within that repository.\nThe core issue is a lack of symlink validation (Time-of-Check Time-of-Use or similar path resolution issues) when the helper attempts to read or import files from the OCI source. The helper assumes that the contents of the OCI repository are safe and strictly confined to the directory being processed.\nAn attacker can exploit this by creating a malicious OCI repository structure where a file that the helper expects to read is replaced by a symbolic link pointing to a sensitive file on the host filesystem (e.g., /etc/shadow or other protected configuration files).\nThe attack flow proceeds as follows: First, the attacker identifies a directory that is processed by the flatpak-system-helper for OCI operations. Second, the attacker populates this directory with an OCI-compliant structure, injecting symbolic links that resolve to sensitive target paths on the host system. Third, the attacker triggers an import action via the system helper, which requests the installation or inspection of the malicious OCI image. Fourth, the helper, running with high privileges, follows the attacker-supplied symlinks during its read operations, inadvertently accessing the target files defined by the attacker. Finally, the contents of the unauthorized files are returned or processed in a way that allows the attacker to retrieve the data or observe the helper's behavior, effectively bypassing mandatory access controls.\nBecause the flatpak-system-helper functions as a privileged daemon, it ignores the standard filesystem permissions that would normally prevent a non-root user from accessing those files. The component fails to sanitize the input paths or employ chroot/namespace-based isolation to restrict file access to the specific OCI source directory during the import process.\nThis vulnerability is limited to the system helper context and requires that system OCI repositories are actively configured and utilized. It does not require remote authentication, as the attack is performed locally by a user capable of placing files within the path accessible by the helper process."
}