CVE-2026-97024: 
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-97024 is a path traversal and symlink-following vulnerability in Flatpak's handling of the files/etc directory during application deployment. A malicious Flatpak app can cause critical host system files — such as /etc/passwd, /etc/group, /etc/machine-id, or /etc/resolv.conf — to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, this write is performed as root. All Flatpak versions prior to 1.18.4 are affected. It carries a CVSS v3.1 base score of 7.1 (High) (Red Hat CVE, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-61 (UNIX Symbolic Link Following), with an estimated CWE-22 (Path Traversal) component. During app deployment, Flatpak does not use file-descriptor-relative operations when processing the files/etc directory, allowing a crafted app to traverse outside the intended sandbox boundary and target host system files. The fix in version 1.18.4 introduces fd-relative helpers for accessing deploy directories (commits 01cd7c4b and cc3ab6ab), preventing the traversal. It is not believed to be possible to replace targeted files with attacker-chosen content — only to empty them or replace them with a specific symlink to /run/host/monitor/resolv.conf. The vulnerability overlaps with a related issue tracked as GHSA-5p67-xh8x-rq54 (CVE-2026-97023) (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation can result in critical host system files being emptied or replaced with symlinks, causing data loss, loss of system access (e.g., emptying /etc/passwd breaks authentication), and disruption of DNS resolution (e.g., replacing /etc/resolv.conf). In system-wide Flatpak installations, these destructive writes are performed as root, amplifying the severity. While confidentiality is not directly impacted, the high availability impact and limited integrity impact reflect the potential to render a system unusable or inaccessible (GitHub Advisory, Red Hat CVE).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation as of the disclosure date (Feedly). Exploitation requires user interaction — specifically, a user must install or upgrade a malicious Flatpak application — but no privileges are required on the attacker's side. The EPSS score is 0.0, reflecting the current absence of observed exploitation activity. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack vector is network-based, as malicious apps can be distributed via Flatpak repositories (GitHub Advisory).

Exploitation steps

  1. Craft a malicious Flatpak app: Create a Flatpak application bundle that includes a specially crafted files/etc directory containing path traversal sequences or symlinks targeting host system files such as passwd, group, machine-id, or resolv.conf.
  2. Distribute the malicious app: Publish the malicious Flatpak app to a public or attacker-controlled Flatpak repository (e.g., a custom OSTree repository) accessible over the network.
  3. Social engineer the victim: Convince a user or administrator to add the attacker's repository and install or upgrade the malicious application, particularly as a system-wide installation (using sudo flatpak install).
  4. Trigger the vulnerability: During the installation or upgrade process, Flatpak processes the files/etc directory without fd-relative protections, allowing the path traversal to resolve to host system paths.
  5. Achieve impact: The targeted host files (e.g., /etc/passwd) are emptied or replaced with a symlink, disrupting authentication, DNS resolution, or system identity — with root-level writes in system-wide installations (GitHub Advisory, Red Hat Bugzilla).

Indicators of compromise

  • File System: /etc/passwd, /etc/group, /etc/machine-id, or /etc/resolv.conf found to be empty (zero bytes) or replaced with a symbolic link, particularly pointing to /run/host/monitor/resolv.conf.
  • File System: Unexpected symlinks or zero-byte files in /etc/ following a Flatpak app installation or upgrade event.
  • Logs: System logs (e.g., journald, /var/log/syslog) showing Flatpak installation or upgrade activity (flatpak install or flatpak update) immediately preceding file modification events on critical /etc/ files.
  • File System: File integrity monitoring alerts on /etc/passwd, /etc/group, /etc/machine-id, or /etc/resolv.conf indicating unexpected modification timestamps or inode changes.
  • Process: flatpak process running as root (system-wide install) with unusual file write activity to /etc/ during app deployment (GitHub Advisory).

Mitigation and workarounds

Upgrade Flatpak to version 1.18.4 or later, which contains the fix via commits 01cd7c4b and cc3ab6ab that introduce fd-relative operations for files/etc handling during deployment (GitHub Advisory). As a workaround, avoid installing Flatpak apps from untrusted publishers, especially system-wide (Red Hat CVE). Additionally, implement file integrity monitoring on /etc/passwd, /etc/group, /etc/machine-id, and /etc/resolv.conf to detect unauthorized modifications. Restrict Flatpak app installation sources to verified, trusted repositories.

Community reactions

The vulnerability was reported by Sebastian Wick and disclosed on September 28, 2026, alongside the Flatpak 1.18.4 release, which addressed six security vulnerabilities in total (Linuxiac). Community coverage highlighted the severity of the two root file-destruction bugs included in the release (Linux Compatible). The issue was also discussed on the oss-security mailing list and tracked by Debian's package tracker (Debian Tracker). Community forums such as Privacy Guides and programming.dev noted the update's importance for users relying on Flatpak for sandboxed application delivery.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

flatpak

Affected

sid

flatpak: 1.18.4-1

Fixed

trixie

flatpak: 1.16.6-1~deb13u3

Fixed

Ubuntu

Unknown

bionic (esm-apps)

flatpak

Unknown

devel

flatpak

Unknown

focal (esm-apps)

flatpak

Unknown

jammy

flatpak

Unknown

jammy (esm-apps)

flatpak

Unknown

noble

flatpak

Unknown

noble (esm-apps)

flatpak

Unknown

resolute

flatpak

Unknown

RHEL / CentOS

Affected

RHEL 8

flatpak.src

Affected

RHEL 9

flatpak.src

Affected

RHEL 10

flatpak.src

Affected

Source: This report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-97024HIGH7.1
  • Linux Debian logoLinux Debian
  • flatpak-selinux
NoYesSep 29, 2026
CVE-2026-97029MEDIUM5.7
  • Linux Debian logoLinux Debian
  • flatpak-devel
NoYesSep 29, 2026
CVE-2026-97026LOW3.9
  • Linux Debian logoLinux Debian
  • flatpak-selinux
NoYesSep 28, 2026
CVE-2026-97027LOW3.6
  • Linux Debian logoLinux Debian
  • flatpak-devel
NoYesSep 28, 2026
CVE-2026-97025LOW3.2
  • Linux Debian logoLinux Debian
  • flatpak-session-helper
NoYesSep 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management