Fedora Account System
Red Hat Associate
Red Hat Customer
TOCTOU race in org.freedesktop.Flatpak.SystemHelper — privileged chmod runs before OSTree repo validation in Deploy(), allowing symlink redirection to arbitrary files.
Flatpak upstream was not involved in the issuing of this CVE ID, and there is some confusion about whether it corresponds to one of the multiple vulnerabilities that were fixed in 1.18.1. Flatpak upstream's official disclosure mechanism for security vulnerabilities is <https://github.com/flatpak/flatpak/security/advisories>. Those vulnerabilities were also disclosed in <https://www.openwall.com/lists/oss-security/2026/08/11/9>. If this CVE corresponds to a public advisory (from its brief description, perhaps it's part of https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp ?), please reference that advisory via its URL or GHSA- ID so that distributors and defenders can correlate the CVE ID with a fix. Or, if this CVE represents an undisclosed vulnerability, please report it to the Flatpak maintainers as described in https://github.com/flatpak/flatpak/blob/main/SECURITY.md#Reporting-a-Vulnerability with full details, so that it can be addressed.