https://seclists.org/oss-sec/2026/q3/913: Flatpak 1.18.1 fixes multiple vulnerabilities
Published Sep 23, 2026
·Updated
Affected Software
1 affected component
Flatpak Flatpak<1.18.1
Frequently Asked Questions
1
Who can exploit these issues?
Both issues are local attacks. The advisory describes one as a local root privilege escalation and the other as a symlink attack that can write fixed filenames to arbitrary locations.
2
What attacker capabilities are involved?
Exploitation involves symlink manipulation. The root escalation issue uses revokefs symlink path traversal and commit tampering, while the arbitrary-write issue targets .ld.so through a symlink attack.
3
Which release addresses the vulnerabilities?
Flatpak 1.18.1 fixes CVE-2026-96808 and CVE-2026-96807.