TOCTOU Race Condition in Flatpak by Red Hat
CVE-2026-76925

5.8MEDIUM

What is CVE-2026-76925?

A vulnerability has been identified in the Flatpak org.freedesktop.Flatpak.SystemHelper component, caused by a Time-of-check to time-of-use (TOCTOU) race condition. This occurs due to a privileged chmod operation that executes before validating the OSTree repository in the Deploy() function. By exploiting this timing vulnerability, an attacker can redirect symlinks to arbitrary files, which may enable unauthorized file manipulation and potentially lead to information disclosure. Users are advised to review security best practices and apply any available patches to mitigate the risk associated with this flaw.

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.