Bug 2542625 (CVE-2026-97024) - CVE-2026-97024 flatpak: flatpak: Arbitrary write in root context via path traversal in deploy directory files/etc
Summary: CVE-2026-97024 flatpak: flatpak: Arbitrary write in root context via path tra...
Keywords:
Status: NEW
Alias: CVE-2026-97024
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-28 19:51 UTC by OSIDB Bzimport
Modified: 2026-09-29 03:17 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-28 19:51:44 UTC
GHSA-8xgq-v545-vgvf (https://github.com/flatpak/flatpak/security/advisories/GHSA-8xgq-v545-vgvf)

Description: A path traversal vulnerability during app installation could be used by an attacker to overwrite system files. A malicious Flatpak app could arrange for files named "passwd", "group", or "machine-id" on the host system (e.g. /etc/passwd) to be emptied when the app is upgraded, resulting in data loss and loss of access to the system. When installing Flatpak apps system-wide, the file write is done by root. It is not believed to be possible to replace these files with attacker-chosen content. Similarly, a malicious app could arrange for files named "resolv.conf" to be replaced by a symbolic link to /run/host/monitor/resolv.conf, which is unlikely to exist on the host system.

Mitigation: No known mitigation other than updating. Patched in 1.18.4 by commits 01cd7c4b ("dir: Add fd-relative helpers for accessing deploy directories") and cc3ab6ab ("dir: Use fd-relative operations for files/etc during runtime deploy"). The changes overlap with those for GHSA-5p67-xh8x-rq54 (CVE-2026-97023).


Note You need to log in before you can comment on or make changes to this bug.