CVE-2026-97024 PUBLISHED

Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory files/etc

Assigner: redhat
Reserved: 23.09.2026 Published: 29.09.2026 Updated: 29.09.2026

A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, the write is performed as root.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
CVSS Score: 7.1

Product Status

Vendor Red Hat
Product Red Hat Enterprise Linux 10
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 7
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 8
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 9
Versions Default: affected

Workarounds

Avoid installing Flatpak apps from untrusted publishers, especially system-wide.

Credits

  • Red Hat would like to thank Sebastian Wick for reporting this issue.

References

Problem Types

  • UNIX Symbolic Link (Symlink) Following CWE