CVE-2026-96283: Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoing pull
By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.
Other sources
GHSA-89xm-3m96-w3jg (https://github.com/flatpak/flatpak/security/advisories/GHSA-89xm-3m96-w3jg)
Description: By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull does not get cancelled but removed from internal tracking, making it impossible to stop it.
Mitigation: No known mitigation other than updating. Patched in 1.16.4 and 1.18.0. Credit: Asim Viladi Oglu Manizada.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
flatpakto a version that resolves this vulnerability.Fixed in 1.16.4 - Upgrade
Upgrade
flatpakto a version that resolves this vulnerability.Fixed in 1.18.0
Event History
Frequently Asked Questions
Who can trigger the issue?
A user who can call org.freedesktop.Flatpak.SystemHelper.CancelPull can invoke it against another user's ongoing pull. The affected pull is removed from internal tracking rather than cancelled.
What is the operational impact if a pull is targeted?
The owning user can no longer stop the ongoing pull. The pull continues running, but it cannot be cancelled through the normal tracking mechanism.
Is there a workaround if updating is not immediately possible?
No known mitigation is available other than updating.
Which releases contain fixes?
The issue is patched in Flatpak 1.16.4 and 1.18.0.