CVE-2026-97027: 
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-97027 is an improper input validation vulnerability in Flatpak that allows a malicious sandboxed application to influence host system behavior beyond its intended sandbox boundaries. When exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, Flatpak passes arbitrary vendor-extension keys through unmodified rather than validating them against an allowlist. This can result in denial of service (e.g., forced application restart loops via X-GNOME-AutoRestart) or unintended interaction with host D-Bus/systemd activation (e.g., via SystemdService). The vulnerability affects Flatpak versions up to and including 1.18.3, with 1.18.4 being the first patched release. It carries a CVSS v3.1 base score of 3.6 (Low) (Red Hat CVE, GitHub Advisory).

Technical details

The root cause is CWE-20 (Improper Input Validation): Flatpak's export logic used a denylist approach, rewriting Exec= to route through the flatpak run wrapper and removing a small set of known-dangerous keys, but passing all other keys — including arbitrary vendor-extension keys — through unmodified. Both .desktop and .service file formats permit arbitrary vendor-extension keys, and desktop environments and D-Bus daemons act on many of them. A malicious app can embed keys such as X-GNOME-AutoRestart=true to cause unconditional restart loops, or SystemdService= to redirect D-Bus daemon activation to a host systemd unit instead of the sandboxed wrapper. The fix, introduced in commit 33931025, switches from a denylist to an allowlist, exporting only keys from a curated list of known-safe entries (GitHub Advisory, Red Hat Bugzilla).

Impact

Exploitation allows a local attacker — who has convinced a victim to install and run a malicious Flatpak application — to cause denial of service through forced application restart loops or to manipulate host D-Bus/systemd service activation behavior outside the intended sandbox restrictions. There is no confidentiality or integrity impact; the primary effect is limited availability disruption. Because the exported files influence the host session environment outside the Flatpak sandbox, the vulnerability is treated as a scope change, though the overall severity remains low (Red Hat CVE, GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires user interaction — a victim must install and run a malicious Flatpak application — which significantly limits the attack surface (Red Hat CVE, GitHub Advisory).

Exploitation steps

  1. Craft a malicious Flatpak application: Create a Flatpak app bundle that includes a .desktop file with a vendor-extension key such as X-GNOME-AutoRestart=true, or a .service file with SystemdService=<host-unit-name> pointing to a host systemd unit.
  2. Distribute the malicious app: Publish the Flatpak bundle through a third-party repository or distribute it directly to a target user, relying on social engineering to convince the victim to install it.
  3. Victim installs and runs the app: Once the victim installs the Flatpak application, Flatpak exports the .desktop and .service files to the host session, passing the malicious vendor-extension keys through unmodified.
  4. Trigger the effect: The host desktop environment or D-Bus daemon reads the exported files and acts on the injected keys — for example, X-GNOME-AutoRestart=true causes the application to restart unconditionally in a loop, or SystemdService= redirects D-Bus activation to an unintended host systemd unit (GitHub Advisory, Red Hat Bugzilla).

Indicators of compromise

  • File System: Presence of .desktop files in ~/.local/share/applications/ or /var/lib/flatpak/exports/share/applications/ containing unexpected vendor-extension keys such as X-GNOME-AutoRestart=true; .service files in ~/.local/share/dbus-1/services/ or /var/lib/flatpak/exports/share/dbus-1/services/ containing a SystemdService= key pointing to a host systemd unit.
  • Logs: Repeated application restart events in GNOME session logs or journald (journalctl) for a Flatpak-hosted application; unexpected D-Bus service activation entries in journalctl referencing host systemd units triggered by a Flatpak app.
  • Process: Abnormal restart loops of a Flatpak application process visible via ps or systemctl status; unexpected systemd unit activations correlated with D-Bus session activity from a Flatpak app (GitHub Advisory, Red Hat CVE).

Mitigation and workarounds

The vulnerability is fixed in Flatpak 1.18.4 via commit 33931025 ("dir: Validate Desktop Entry and D-Bus Service"), which switches from a denylist to an allowlist for exported file keys. Users should upgrade to Flatpak 1.18.4 or later as soon as possible. As a workaround, only install Flatpak applications from trusted, verified sources to reduce exposure (GitHub Advisory, Red Hat CVE, Red Hat Bugzilla).

Community reactions

The vulnerability was reported by security researcher Markus Göllnitz and disclosed alongside five other security fixes in the Flatpak 1.18.4 release, which received coverage from Linux-focused outlets including Linuxiac and LinuxCompatible highlighting the six-vulnerability release (Linuxiac, LinuxCompatible). Community discussion appeared on Privacy Guides forums and programming.dev, with general sentiment reflecting low urgency given the Low severity rating and the requirement for user interaction. Debian's package tracker also flagged the issue for action (Debian Tracker).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

flatpak

Affected

sid

flatpak: 1.18.4-1

Fixed

trixie

flatpak: 1.16.6-1~deb13u3

Fixed

RHEL / CentOS

Affected

RHEL 8

flatpak.src

Affected

RHEL 9

flatpak.src

Affected

RHEL 10

flatpak.src

Affected

Source: This report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-97023HIGH7.1
  • Linux Debian logoLinux Debian
  • flatpak-devel
NoYesSep 28, 2026
CVE-2026-101913MEDIUM6.3
  • JavaScript logoJavaScript
  • node-ip-address
NoYesSep 28, 2026
CVE-2026-97026LOW3.9
  • Linux Debian logoLinux Debian
  • flatpak
NoYesSep 28, 2026
CVE-2026-97027LOW3.6
  • Linux Debian logoLinux Debian
  • flatpak.src
NoYesSep 28, 2026
CVE-2026-97025LOW3.2
  • Linux Debian logoLinux Debian
  • flatpak-selinux
NoYesSep 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management