Bug 2520099 (CVE-2026-76925) - CVE-2026-76925 flatpak: Flatpak: TOCTOU race condition allows symlink redirection
Summary: CVE-2026-76925 flatpak: Flatpak: TOCTOU race condition allows symlink redirec...
Keywords:
Status: NEW
Alias: CVE-2026-76925
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2524927
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-19 23:06 UTC by OSIDB Bzimport
Modified: 2026-09-08 11:21 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-19 23:06:43 UTC
TOCTOU race in org.freedesktop.Flatpak.SystemHelper — privileged chmod runs before OSTree repo validation in Deploy(), allowing symlink redirection to arbitrary files.

Comment 2 Simon McVittie 2026-09-08 11:21:22 UTC
Flatpak upstream was not involved in the issuing of this CVE ID, and there is some confusion about whether it corresponds to one of the multiple vulnerabilities that were fixed in 1.18.1. Flatpak upstream's official disclosure mechanism for security vulnerabilities is <https://github.com/flatpak/flatpak/security/advisories>. Those vulnerabilities were also disclosed in <https://www.openwall.com/lists/oss-security/2026/08/11/9>.

If this CVE corresponds to a public advisory (from its brief description, perhaps it's part of https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp ?), please reference that advisory via its URL or GHSA- ID so that distributors and defenders can correlate the CVE ID with a fix.

Or, if this CVE represents an undisclosed vulnerability, please report it to the Flatpak maintainers as described in https://github.com/flatpak/flatpak/blob/main/SECURITY.md#Reporting-a-Vulnerability with full details, so that it can be addressed.


Note You need to log in before you can comment on or make changes to this bug.