Vulnerability in Flatpak Application Exports by Red Hat
CVE-2026-97027

3.6LOW

What is CVE-2026-97027?

A vulnerability exists in Flatpak due to improper handling of vendor-specific keys during the export of application Desktop Entry and D-Bus Service files. This flaw allows malicious applications to bypass intended security restrictions, potentially leading to denial of service or unwarranted alterations in host D-Bus/systemd activation behavior. Such exploitation can disrupt user experiences by causing application restart loops or altering system behavior beyond sandbox limits.

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Markus Göllnitz for reporting this issue.
.