CVE-2026-97027: Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus service files

Published Sep 28, 2026
·
Updated

Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, instead of validating against an allowlist. A malicious Flatpak app can use this to cause denial of service (e.g. forced application restart loops) or to influence host D-Bus/systemd activation behavior beyond what the sandbox is intended to permit.

Other sources

GHSA-v64f-hrwr-j4vh (https://github.com/flatpak/flatpak/security/advisories/GHSA-v64f-hrwr-j4vh)

Description: A malicious Flatpak application can influence host system behavior beyond its sandbox by including arbitrary keys in its exported Desktop Entry (.desktop) or D-Bus Service (.service) files. This can lead to denial of service (e.g. X-GNOME-AutoRestart causing unconditional application restarts) or unintended interaction with host services (e.g. SystemdService directing the D-Bus daemon to activate a host systemd unit instead of the sandboxed wrapper). When Flatpak exports these files, it rewrites Exec= to go through the flatpak run wrapper and removes a small denylist of known-dangerous keys, but passes all other keys through unmodified. The fix switches from a denylist to an allowlist, exporting only keys from a curated list of known-safe entries.

Mitigation: Only install applications from trusted sources. Patched in 1.18.4 by commit 33931025 ("dir: Validate Desktop Entry and D-Bus Service"). Credit: Reported by Markus Göllnitz.

— Red Hat

Affected Software

1 affected component
Flatpak Flatpak<1.18.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Flatpak to a version that resolves this vulnerability.

    Fixed in 1.18.4
  2. Compensating control

    Only install Flatpak applications from trusted sources.

Event History

Sep 28, 2026
Data Sourced
via Red Hat·08:36 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·08:57 PM
Data Sourced
via MITRE·08:57 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What conditions are required for exploitation?

The attacker needs a malicious Flatpak application that includes arbitrary vendor-extension keys in files Flatpak exports to the host. The supplied vector indicates user interaction is required, but does not specify the exact interaction.

2

Does Flatpak's rewriting of the Exec field prevent this issue?

No. Flatpak rewrites Exec= to use the flatpak run wrapper, but previously passed non-denylisted keys through unmodified. The unsafe behavior is in those additional exported Desktop Entry and D-Bus Service keys.

3

What host-side effects should defenders look for?

Potential effects include application restart loops, such as through X-GNOME-AutoRestart, and unexpected D-Bus activation behavior. A SystemdService key may cause the D-Bus daemon to activate a host systemd unit rather than the intended sandboxed wrapper.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203