REDHAT-BUG-2542637: Low severity Flatpak Flatpak vulnerability

Published Sep 28, 2026
·
Updated

GHSA-r9w3-qx54-qvc8 (https://github.com/flatpak/flatpak/security/advisories/GHSA-r9w3-qx54-qvc8)

Description: The child temporary directories allocated under the user cache (/var/tmp/flatpak-cache-) are created with mode 0777. On multi-user systems this could allow other local users to modify the app as it is being installed. This is related to GHSA-7rvf-rqr3-43j4 (CVE-2026-97025) but with a different impact. This is mitigated by a restrictive umask; it is believed to be a denial-of-service risk rather than an integrity threat, because a modified app/runtime would fail its signature or digest check. The flatpak(1) CLI, GNOME Software, and KDE Plasma Discover are believed unaffected since they set umask 022; other software using libflatpak with a permissive umask might be indirectly vulnerable.

Mitigation: Set a umask that does not allow other users to write to the cache directory (e.g. umask 022). Patched in 1.18.4 by commit 011dfae2 ("common: Restrict tmpdir permissions from 0777 to 0755"). Credit: Found by AISLE in cooperation with Red Hat.

Affected Software

1 affected component
Flatpak Flatpak<1.18.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade flatpak to a version that resolves this vulnerability.

    Fixed in 1.18.4
  2. Configuration

    Set a restrictive umask, such as 022, so other users cannot write to the cache directory.

    libflatpak applications umask = 022

Event History

Sep 28, 2026
Data Sourced
via Red Hat·08:16 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which deployments are realistically exposed?

The risk is limited to multi-user systems where software uses libflatpak with a permissive umask. The flatpak CLI, GNOME Software, and KDE Plasma Discover are believed unaffected because they set umask 022.

2

What would an attacker need to exploit this?

An attacker would need to be another local user able to modify world-writable temporary directories under /var/tmp/flatpak-cache-* while an application is being installed. The described impact is believed to be denial of service, since modified apps or runtimes should fail signature or digest verification.

3

What can be done before updating?

Ensure the process using libflatpak runs with a restrictive umask that prevents other users from writing to its cache directories, such as umask 022. This mitigates creation of writable temporary cache directories.

4

Which release contains the fix?

The issue is patched in Flatpak 1.18.4. The fix changes temporary-directory permissions from 0777 to 0755.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203