
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-97024 is a path traversal and symlink-following vulnerability in Flatpak's handling of the files/etc directory during application deployment. A malicious Flatpak app can cause critical host system files — such as /etc/passwd, /etc/group, /etc/machine-id, or /etc/resolv.conf — to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, this write is performed as root. All Flatpak versions prior to 1.18.4 are affected. It carries a CVSS v3.1 base score of 7.1 (High) (Red Hat CVE, GitHub Advisory).
The vulnerability is classified as CWE-61 (UNIX Symbolic Link Following), with an estimated CWE-22 (Path Traversal) component. During app deployment, Flatpak does not use file-descriptor-relative operations when processing the files/etc directory, allowing a crafted app to traverse outside the intended sandbox boundary and target host system files. The fix in version 1.18.4 introduces fd-relative helpers for accessing deploy directories (commits 01cd7c4b and cc3ab6ab), preventing the traversal. It is not believed to be possible to replace targeted files with attacker-chosen content — only to empty them or replace them with a specific symlink to /run/host/monitor/resolv.conf. The vulnerability overlaps with a related issue tracked as GHSA-5p67-xh8x-rq54 (CVE-2026-97023) (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation can result in critical host system files being emptied or replaced with symlinks, causing data loss, loss of system access (e.g., emptying /etc/passwd breaks authentication), and disruption of DNS resolution (e.g., replacing /etc/resolv.conf). In system-wide Flatpak installations, these destructive writes are performed as root, amplifying the severity. While confidentiality is not directly impacted, the high availability impact and limited integrity impact reflect the potential to render a system unusable or inaccessible (GitHub Advisory, Red Hat CVE).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation as of the disclosure date (Feedly). Exploitation requires user interaction — specifically, a user must install or upgrade a malicious Flatpak application — but no privileges are required on the attacker's side. The EPSS score is 0.0, reflecting the current absence of observed exploitation activity. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack vector is network-based, as malicious apps can be distributed via Flatpak repositories (GitHub Advisory).
files/etc directory containing path traversal sequences or symlinks targeting host system files such as passwd, group, machine-id, or resolv.conf.sudo flatpak install).files/etc directory without fd-relative protections, allowing the path traversal to resolve to host system paths./etc/passwd) are emptied or replaced with a symlink, disrupting authentication, DNS resolution, or system identity — with root-level writes in system-wide installations (GitHub Advisory, Red Hat Bugzilla)./etc/passwd, /etc/group, /etc/machine-id, or /etc/resolv.conf found to be empty (zero bytes) or replaced with a symbolic link, particularly pointing to /run/host/monitor/resolv.conf./etc/ following a Flatpak app installation or upgrade event.journald, /var/log/syslog) showing Flatpak installation or upgrade activity (flatpak install or flatpak update) immediately preceding file modification events on critical /etc/ files./etc/passwd, /etc/group, /etc/machine-id, or /etc/resolv.conf indicating unexpected modification timestamps or inode changes.flatpak process running as root (system-wide install) with unusual file write activity to /etc/ during app deployment (GitHub Advisory).Upgrade Flatpak to version 1.18.4 or later, which contains the fix via commits 01cd7c4b and cc3ab6ab that introduce fd-relative operations for files/etc handling during deployment (GitHub Advisory). As a workaround, avoid installing Flatpak apps from untrusted publishers, especially system-wide (Red Hat CVE). Additionally, implement file integrity monitoring on /etc/passwd, /etc/group, /etc/machine-id, and /etc/resolv.conf to detect unauthorized modifications. Restrict Flatpak app installation sources to verified, trusted repositories.
The vulnerability was reported by Sebastian Wick and disclosed on September 28, 2026, alongside the Flatpak 1.18.4 release, which addressed six security vulnerabilities in total (Linuxiac). Community coverage highlighted the severity of the two root file-destruction bugs included in the release (Linux Compatible). The issue was also discussed on the oss-security mailing list and tracked by Debian's package tracker (Debian Tracker). Community forums such as Privacy Guides and programming.dev noted the update's importance for users relying on Flatpak for sandboxed application delivery.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
flatpak
devel
flatpak
focal (esm-apps)
flatpak
jammy
flatpak
jammy (esm-apps)
flatpak
noble
flatpak
noble (esm-apps)
flatpak
resolute
flatpak
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."