TOCTOU Race Condition in Flatpak by Red Hat
CVE-2026-76925
5.8MEDIUM
What is CVE-2026-76925?
A vulnerability has been identified in the Flatpak org.freedesktop.Flatpak.SystemHelper component, caused by a Time-of-check to time-of-use (TOCTOU) race condition. This occurs due to a privileged chmod operation that executes before validating the OSTree repository in the Deploy() function. By exploiting this timing vulnerability, an attacker can redirect symlinks to arbitrary files, which may enable unauthorized file manipulation and potentially lead to information disclosure. Users are advised to review security best practices and apply any available patches to mitigate the risk associated with this flaw.