Sceawere
Vulnerability Detail
CVE-2026-97024UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Flatpak Filesystem Path Traversal Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- Attack Type
- UNIX Symbolic Link (Symlink) Following
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, the write is performed as root.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-29T04:18:02.397Z",
"pubdate": "2026-09-29T04:18:02.397Z",
"executiveSummary": "A path traversal vulnerability exists within Flatpak's deployment mechanism related to the handling of the files/etc directory. This flaw allows a malicious Flatpak application package to escape its designated sandbox directory and manipulate arbitrary files on the host filesystem during the installation or upgrade process.\nThe vulnerability is particularly critical for system-wide Flatpak installations, where the deployment operations are executed with root privileges. By injecting path traversal sequences into the package metadata or file structure, an attacker can coerce the installation process into overwriting, emptying, or replacing sensitive host configuration files such as /etc/passwd, /etc/group, /etc/machine-id, or /etc/resolv.conf.\nThe impact includes potential local privilege escalation, system denial of service, and the ability to modify host authentication or network configuration parameters. Exploitation requires a user to install or upgrade a specially crafted malicious Flatpak application. No network exposure is inherently required beyond the ability to distribute the malicious package, making this a significant threat to system integrity in environments where untrusted Flatpak sources are utilized.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient sanitization of file paths contained within Flatpak application bundles, specifically concerning the 'files/etc' directory during the deployment phase. When the Flatpak helper utility processes the application manifest and extracts the package contents into the target directory, it fails to properly validate and restrict file paths against parent directory traversal sequences (e.g., '../').\nDuring the installation or upgrade sequence, the Flatpak deployment engine attempts to link or copy files from the bundle into the host's system configuration space. If the package contains entries designed to traverse outside the expected directory structure, the underlying filesystem operations can be manipulated to operate on target files located outside the intended sandbox boundary.\nIn the context of system-wide installations, the Flatpak daemon or helper utility operates with root privileges to perform necessary filesystem modifications. Because the path validation logic is bypassed, these escalated privileges are inadvertently applied to the malicious path provided by the package. For instance, if an attacker crafts a package with a symlink or file entry pointing to '/etc/passwd', the installer, running as root, may follow the traversal and either overwrite the existing file with empty data or replace the legitimate system file with a symlink controlled by the attacker.\nThe attack flow proceeds as follows: 1) An attacker creates a malicious Flatpak bundle containing carefully crafted file paths incorporating path traversal characters. 2) The victim triggers the installation or upgrade of the malicious application. 3) The Flatpak installer interprets the malicious paths during the deployment process. 4) Due to the lack of path sanitization, the installer writes, links, or truncates sensitive host files located at the destination specified by the traversal. 5) The integrity of the host system is compromised, potentially leading to unauthorized modification of user databases, service configuration, or network resolution settings. This vulnerability does not require authentication from the victim other than the action of installing the application, and the success of the attack relies heavily on the privilege level of the installation process."
}