CVE-2026-76925: Flatpak: flatpak: toctou race condition allows symlink redirection

Published Aug 19, 2026
·
Updated

A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the org.freedesktop.Flatpak.SystemHelper component. This vulnerability occurs because a privileged chmod operation executes before the OSTree repository validation within the Deploy() function. An attacker can exploit this timing window to redirect symlinks to arbitrary files, potentially leading to unauthorized file manipulation or information disclosure.

Other sources

TOCTOU race in org.freedesktop.Flatpak.SystemHelper — privileged chmod runs before OSTree repo validation in Deploy(), allowing symlink redirection to arbitrary files.

— Red Hat

Affected Software

2 affected componentsFixes available
Flatpak Flatpak
debian/flatpak
1.14.10-1~deb12u21.16.6-1~deb13u21.18.2-11.18.3-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/flatpak to a version that resolves this vulnerability.

    Fixed in 1.14.10-1~deb12u2Fixed in 1.16.6-1~deb13u2Fixed in 1.18.2-1Fixed in 1.18.3-1

Event History

Aug 19, 2026
Data Sourced
via Red Hat·11:06 PM
DescriptionSeverityAffected Software
Sep 4, 2026
CVE Published
via MITRE·09:02 PM
Data Sourced
via MITRE·09:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness
Sep 23, 2026
Data Sourced
via Debian·02:00 AM
DescriptionAffected Software

Frequently Asked Questions

1

What level of access does an attacker need to exploit this issue?

The attacker needs local access and low privileges. Exploitation also requires winning a high-complexity timing race; no user interaction is required.

2

Which component is involved in the vulnerable operation?

The issue is in the org.freedesktop.Flatpak.SystemHelper component, specifically during the Deploy() function. A privileged chmod operation occurs before OSTree repository validation.

3

What could successful exploitation allow?

An attacker may redirect symlinks to arbitrary files during the race window. This can result in unauthorized file manipulation or information disclosure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203