REDHAT-BUG-2542625: Path Traversal
GHSA-8xgq-v545-vgvf (https://github.com/flatpak/flatpak/security/advisories/GHSA-8xgq-v545-vgvf)
Description: A path traversal vulnerability during app installation could be used by an attacker to overwrite system files. A malicious Flatpak app could arrange for files named "passwd", "group", or "machine-id" on the host system (e.g. /etc/passwd) to be emptied when the app is upgraded, resulting in data loss and loss of access to the system. When installing Flatpak apps system-wide, the file write is done by root. It is not believed to be possible to replace these files with attacker-chosen content. Similarly, a malicious app could arrange for files named "resolv.conf" to be replaced by a symbolic link to /run/host/monitor/resolv.conf, which is unlikely to exist on the host system.
Mitigation: No known mitigation other than updating. Patched in 1.18.4 by commits 01cd7c4b ("dir: Add fd-relative helpers for accessing deploy directories") and cc3ab6ab ("dir: Use fd-relative operations for files/etc during runtime deploy"). The changes overlap with those for GHSA-5p67-xh8x-rq54 (CVE-2026-97023).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Flatpakto a version that resolves this vulnerability.Fixed in 1.18.4Patch GHSA-8xgq-v545-vgvf
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems that install or upgrade a malicious Flatpak app system-wide are exposed. In that installation mode, the affected file operation is performed as root, so host files such as /etc/passwd, /etc/group, or /etc/machine-id can be emptied.
What must an attacker do to trigger the vulnerability?
An attacker needs to provide a malicious Flatpak app and have it installed or upgraded. The app can arrange for host files with names such as passwd, group, or machine-id to be emptied during an upgrade.
Can the attacker replace host files with arbitrary content?
The available information indicates that replacing the files with attacker-chosen content is not believed to be possible. The described impact is data loss and possible loss of access to the system when critical files are emptied.
What can be done if updating is not immediately possible?
No mitigation other than updating is known. Flatpak 1.18.4 includes the identified fixes.