In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. The filenames and content are not attacker controlled, making this hard to exploit.

Project Subscriptions

Vendors Products
Flatpak Subscribe
Flatpak Subscribe
Advisories

No advisories yet.

Fixes

Solution

The issue has been fixed in version 1.18.1 by commits: * e13dfed https://github.com/flatpak/flatpak/commit/e13dfeda330625d2fecc3a54672dfd4dc9c83a5c "common: Fix return value and typos in flatpak_switch_symlink_and_remove" * f6c8fb5 https://github.com/flatpak/flatpak/commit/f6c8fb5fdb3737e2f45068afe12c4bf1d808fd55 "common: Use fd-based operations in flatpak_switch_symlink_and_remove" * 76c9296 https://github.com/flatpak/flatpak/commit/76c9296b6780ca67f44cf67f0823f086d692a592 "run: Harden regenerate_ld_cache against symlink attacks" For LTS operating system distributions, backports of these changes are available in the flatpak-1.16.x branch. Please note that cherry-picked libglnx changes "chase: Add internal glnx_chaseat_full for a strategic callback" and "chase: Add glnx_chase_and_mkdirat" are also required.


Workaround

No workaround given by the vendor.

History

Wed, 23 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Flatpak LD Cache Symlink Attack

Wed, 23 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. The filenames and content are not attacker controlled, making this hard to exploit.
First Time appeared Flatpak
Flatpak flatpak
Weaknesses CWE-61
CPEs cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:*
Vendors & Products Flatpak
Flatpak flatpak
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-23T16:54:16.931Z

Reserved: 2026-09-23T16:54:16.535Z

Link: CVE-2026-96807

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T17:17:25.703

Modified: 2026-09-23T17:17:25.703

Link: CVE-2026-96807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T18:30:06Z

Weaknesses