REDHAT-BUG-2542637: Low severity Flatpak Flatpak vulnerability
GHSA-r9w3-qx54-qvc8 (https://github.com/flatpak/flatpak/security/advisories/GHSA-r9w3-qx54-qvc8)
Description: The child temporary directories allocated under the user cache (/var/tmp/flatpak-cache-) are created with mode 0777. On multi-user systems this could allow other local users to modify the app as it is being installed. This is related to GHSA-7rvf-rqr3-43j4 (CVE-2026-97025) but with a different impact. This is mitigated by a restrictive umask; it is believed to be a denial-of-service risk rather than an integrity threat, because a modified app/runtime would fail its signature or digest check. The flatpak(1) CLI, GNOME Software, and KDE Plasma Discover are believed unaffected since they set umask 022; other software using libflatpak with a permissive umask might be indirectly vulnerable.
Mitigation: Set a umask that does not allow other users to write to the cache directory (e.g. umask 022). Patched in 1.18.4 by commit 011dfae2 ("common: Restrict tmpdir permissions from 0777 to 0755"). Credit: Found by AISLE in cooperation with Red Hat.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
flatpakto a version that resolves this vulnerability.Fixed in 1.18.4 - Configuration
Set a restrictive umask, such as 022, so other users cannot write to the cache directory.
libflatpak applications umask = 022
Event History
Frequently Asked Questions
Which deployments are realistically exposed?
The risk is limited to multi-user systems where software uses libflatpak with a permissive umask. The flatpak CLI, GNOME Software, and KDE Plasma Discover are believed unaffected because they set umask 022.
What would an attacker need to exploit this?
An attacker would need to be another local user able to modify world-writable temporary directories under /var/tmp/flatpak-cache-* while an application is being installed. The described impact is believed to be denial of service, since modified apps or runtimes should fail signature or digest verification.
What can be done before updating?
Ensure the process using libflatpak runs with a restrictive umask that prevents other users from writing to its cache directories, such as umask 022. This mitigates creation of writable temporary cache directories.
Which release contains the fix?
The issue is patched in Flatpak 1.18.4. The fix changes temporary-directory permissions from 0777 to 0755.