A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
Remove all OCI system remotes.
References
History
Sun, 27 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control. | |
| Title | Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci symlink following | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-27T22:20:48.851Z
Reserved: 2026-09-22T20:44:18.585Z
Link: CVE-2026-96284
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses