Fedora Account System
Red Hat Associate
Red Hat Customer
GHSA-8xgq-v545-vgvf (https://github.com/flatpak/flatpak/security/advisories/GHSA-8xgq-v545-vgvf) Description: A path traversal vulnerability during app installation could be used by an attacker to overwrite system files. A malicious Flatpak app could arrange for files named "passwd", "group", or "machine-id" on the host system (e.g. /etc/passwd) to be emptied when the app is upgraded, resulting in data loss and loss of access to the system. When installing Flatpak apps system-wide, the file write is done by root. It is not believed to be possible to replace these files with attacker-chosen content. Similarly, a malicious app could arrange for files named "resolv.conf" to be replaced by a symbolic link to /run/host/monitor/resolv.conf, which is unlikely to exist on the host system. Mitigation: No known mitigation other than updating. Patched in 1.18.4 by commits 01cd7c4b ("dir: Add fd-relative helpers for accessing deploy directories") and cc3ab6ab ("dir: Use fd-relative operations for files/etc during runtime deploy"). The changes overlap with those for GHSA-5p67-xh8x-rq54 (CVE-2026-97023).