CVE-2026-97024: Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory files/etc
A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, the write is performed as root.
Other sources
GHSA-8xgq-v545-vgvf (https://github.com/flatpak/flatpak/security/advisories/GHSA-8xgq-v545-vgvf)
Description: A path traversal vulnerability during app installation could be used by an attacker to overwrite system files. A malicious Flatpak app could arrange for files named "passwd", "group", or "machine-id" on the host system (e.g. /etc/passwd) to be emptied when the app is upgraded, resulting in data loss and loss of access to the system. When installing Flatpak apps system-wide, the file write is done by root. It is not believed to be possible to replace these files with attacker-chosen content. Similarly, a malicious app could arrange for files named "resolv.conf" to be replaced by a symbolic link to /run/host/monitor/resolv.conf, which is unlikely to exist on the host system.
Mitigation: No known mitigation other than updating. Patched in 1.18.4 by commits 01cd7c4b ("dir: Add fd-relative helpers for accessing deploy directories") and cc3ab6ab ("dir: Use fd-relative operations for files/etc during runtime deploy"). The changes overlap with those for GHSA-5p67-xh8x-rq54 (CVE-2026-97023).
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Flatpakto a version that resolves this vulnerability.Fixed in 1.18.4
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems that install or upgrade a malicious Flatpak app are exposed. System-wide installations are particularly severe because the affected file write is performed as root.
What must an attacker do to exploit it?
An attacker must provide a malicious Flatpak app and have it installed or upgraded on the target system. User interaction is required, as reflected by the UI:R vector.
What is the expected impact on host files?
The issue can cause certain host files, including passwd, group, or machine-id, to be emptied, potentially causing data loss or loss of access to the system. It is not believed that an attacker can replace those files with attacker-chosen content; resolv.conf may instead be replaced with a symlink to /run/host/monitor/resolv.conf.
Is there a mitigation if patching cannot be done immediately?
No known mitigation is provided other than updating.