Vulnerability in Flatpak Application Exports by Red Hat
CVE-2026-97027
3.6LOW
What is CVE-2026-97027?
A vulnerability exists in Flatpak due to improper handling of vendor-specific keys during the export of application Desktop Entry and D-Bus Service files. This flaw allows malicious applications to bypass intended security restrictions, potentially leading to denial of service or unwarranted alterations in host D-Bus/systemd activation behavior. Such exploitation can disrupt user experiences by causing application restart loops or altering system behavior beyond sandbox limits.
References
CVSS V3.1
Score:
3.6
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Markus Göllnitz for reporting this issue.