Bug 2520099 (CVE-2026-76925)
| Summary: | CVE-2026-76925 flatpak: Flatpak: TOCTOU race condition allows symlink redirection | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, simon.mcvittie, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTree repository validation within the `Deploy()` function. An attacker can exploit this timing window to redirect symlinks to arbitrary files, potentially leading to unauthorized file manipulation or information disclosure.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2524927 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-08-19 23:06:43 UTC
Flatpak upstream was not involved in the issuing of this CVE ID, and there is some confusion about whether it corresponds to one of the multiple vulnerabilities that were fixed in 1.18.1. Flatpak upstream's official disclosure mechanism for security vulnerabilities is <https://github.com/flatpak/flatpak/security/advisories>. Those vulnerabilities were also disclosed in <https://www.openwall.com/lists/oss-security/2026/08/11/9>. If this CVE corresponds to a public advisory (from its brief description, perhaps it's part of https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp ?), please reference that advisory via its URL or GHSA- ID so that distributors and defenders can correlate the CVE ID with a fix. Or, if this CVE represents an undisclosed vulnerability, please report it to the Flatpak maintainers as described in https://github.com/flatpak/flatpak/blob/main/SECURITY.md#Reporting-a-Vulnerability with full details, so that it can be addressed. Debian's security team has been in contact with Red Hat's security team and according to https://security-tracker.debian.org/tracker/CVE-2026-76925 they have received information saying that the scope of CVE-2026-76925 only covers Red Hat's packaged versions of older Flatpak branches, and does not cover upstream Flatpak. I would very much appreciate it if Red Hat's security team could make it very, very obvious in the CVE description if a CVE ID does not affect upstream. The Flatpak upstream maintainers and the Debian security team have had to spend a significant amount of time chasing this, and that's time that we could have been spending on fixing vulnerabilities instead. |