CVE-2026-96279: Flatpak: flatpak: path traversal issue in oci archive extraction via hardlinks
A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide installs running as root, this includes sensitive files such as /etc/shadow.
Other sources
GHSA-9rww-v4mm-x4jg (https://github.com/flatpak/flatpak/security/advisories/GHSA-9rww-v4mm-x4jg)
Description: When extracting OCI layer archives, Flatpak rebases archive entry pathnames to the destination directory using gbuildfilename, and sets ARCHIVEEXTRACTSECURENODOTDOT to reject .. components in both pathnames and hardlink targets. However, hardlink targets were not rebased to the destination directory. A crafted archive entry with an absolute hardlink target (e.g. /etc/shadow) causes libarchive to call link() with that path directly, hardlinking the host file into the extraction directory and making its contents readable. An attacker controlling an OCI registry can serve a crafted layer archive that exploits this during flatpak install or flatpak update.
Mitigation: Only install applications from trusted OCI registries. Flatpak remotes using the default OSTree transport are not affected. Versions 1.16.x and older are not believed to be vulnerable (introduced in 1.17.0). Fixed in 1.18.1. Reported by @swick.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Flatpakto a version that resolves this vulnerability.Fixed in 1.18.1 - Compensating control
Only install applications from trusted OCI registries; Flatpak remotes using the default OSTree transport are not affected.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users who install or update Flatpak applications from an OCI remote are exposed if that OCI registry is malicious or attacker-controlled. System-wide installs running as root can expose sensitive host files, including /etc/shadow.
Does this affect the default Flatpak remote configuration?
The provided mitigation states that Flatpak remotes using the default OSTree transport are not affected. The issue applies to OCI remotes during OCI layer archive extraction.
What does an attacker need to exploit it?
An attacker must control, or be able to serve malicious content from, an OCI registry used as a Flatpak remote. They then need a user or system process to install or update an application from that remote.
What can be done if patching is not immediately possible?
Only install applications from trusted OCI registries. Avoid installing or updating applications from untrusted OCI remotes until the issue is addressed.