https://seclists.org/oss-sec/2026/q3/877: Flatpak 1.18.1 fixes multiple vulnerabilities
Published Sep 22, 2026
·Updated
Affected Software
1 affected component
Flatpak Flatpak<1.18.1
Frequently Asked Questions
1
Which issues can lead to modification of host or root-owned files?
The app-data-directory symlink flaw can provide full host filesystem read/write access. Separate issues allow arbitrary root writes during extra-data extraction and flatpak build-init, while the revokefs flaw can enable local root privilege escalation through symlink path traversal and commit tampering.
2
Which issues expose host-file contents?
The app-data-directory symlink issue can expose the full host filesystem for reading. A separate OCI archive extraction flaw can cause arbitrary host-file reads through hardlink path traversal.
3
Are all of the listed issues assigned CVE identifiers?
No. The revokefs symlink path traversal and commit-tampering issue has a CVE request pending with reference CAN-2026-2052453. The other explicitly identified issues are CVE-2026-90616, CVE-2026-96275, and CVE-2026-96276.