REDHAT-BUG-2539417: Medium severity Flatpak Flatpak vulnerability

Published Sep 23, 2026
·
Updated

GHSA-9rww-v4mm-x4jg (https://github.com/flatpak/flatpak/security/advisories/GHSA-9rww-v4mm-x4jg)

Description: When extracting OCI layer archives, Flatpak rebases archive entry pathnames to the destination directory using gbuildfilename, and sets ARCHIVEEXTRACTSECURENODOTDOT to reject .. components in both pathnames and hardlink targets. However, hardlink targets were not rebased to the destination directory. A crafted archive entry with an absolute hardlink target (e.g. /etc/shadow) causes libarchive to call link() with that path directly, hardlinking the host file into the extraction directory and making its contents readable. An attacker controlling an OCI registry can serve a crafted layer archive that exploits this during flatpak install or flatpak update.

Mitigation: Only install applications from trusted OCI registries. Flatpak remotes using the default OSTree transport are not affected. Versions 1.16.x and older are not believed to be vulnerable (introduced in 1.17.0). Fixed in 1.18.1. Reported by @swick.

Affected Software

1 affected component
Flatpak Flatpak>=1.17.0<1.18.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Flatpak to a version that resolves this vulnerability.

    Fixed in 1.18.1
  2. Compensating control

    Only install applications from trusted OCI registries.

Event History

Sep 23, 2026
Data Sourced
via Red Hat·02:01 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which Flatpak installations are exposed to this issue?

Installations using OCI-based Flatpak remotes may be exposed if they run a vulnerable version. Remotes using Flatpak's default OSTree transport are not affected, and versions 1.16.x and older are not believed to be vulnerable.

2

What does an attacker need to exploit this?

The attacker must control an OCI registry used by the target system and serve a crafted OCI layer archive. Exploitation occurs during a flatpak install or flatpak update from that registry.

3

What can be done if updating Flatpak is not immediately possible?

Install applications only from trusted OCI registries. Avoid installing or updating from OCI registries that could be attacker-controlled; default OSTree-based remotes are not affected.

4

How can I determine whether I may already be affected?

Check whether the system uses OCI-based Flatpak remotes and whether it runs Flatpak 1.17.0 or later before the fix in 1.18.1. The issue can cause host files referenced by crafted absolute hardlink targets to be linked into the extraction directory and made readable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203