Bug 2520099 (CVE-2026-76925)

Summary: CVE-2026-76925 flatpak: Flatpak: TOCTOU race condition allows symlink redirection
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: rhel-process-autobot, simon.mcvittie, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTree repository validation within the `Deploy()` function. An attacker can exploit this timing window to redirect symlinks to arbitrary files, potentially leading to unauthorized file manipulation or information disclosure.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2524927    
Bug Blocks:    

Description OSIDB Bzimport 2026-08-19 23:06:43 UTC
TOCTOU race in org.freedesktop.Flatpak.SystemHelper — privileged chmod runs before OSTree repo validation in Deploy(), allowing symlink redirection to arbitrary files.

Comment 2 Simon McVittie 2026-09-08 11:21:22 UTC
Flatpak upstream was not involved in the issuing of this CVE ID, and there is some confusion about whether it corresponds to one of the multiple vulnerabilities that were fixed in 1.18.1. Flatpak upstream's official disclosure mechanism for security vulnerabilities is <https://github.com/flatpak/flatpak/security/advisories>. Those vulnerabilities were also disclosed in <https://www.openwall.com/lists/oss-security/2026/08/11/9>.

If this CVE corresponds to a public advisory (from its brief description, perhaps it's part of https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp ?), please reference that advisory via its URL or GHSA- ID so that distributors and defenders can correlate the CVE ID with a fix.

Or, if this CVE represents an undisclosed vulnerability, please report it to the Flatpak maintainers as described in https://github.com/flatpak/flatpak/blob/main/SECURITY.md#Reporting-a-Vulnerability with full details, so that it can be addressed.

Comment 3 Simon McVittie 2026-09-22 14:56:53 UTC
Debian's security team has been in contact with Red Hat's security team and according to https://security-tracker.debian.org/tracker/CVE-2026-76925 they have received information saying that the scope of CVE-2026-76925 only covers Red Hat's packaged versions of older Flatpak branches, and does not cover upstream Flatpak.

I would very much appreciate it if Red Hat's security team could make it very, very obvious in the CVE description if a CVE ID does not affect upstream. The Flatpak upstream maintainers and the Debian security team have had to spend a significant amount of time chasing this, and that's time that we could have been spending on fixing vulnerabilities instead.