OCI 增量流解析器将读取的大小作为 处理,但将其传递给期望使用 (在 32 位系统中为 32 位)的 GLib I/O 和内存分配函数,导致分配的内存空间不足,而后续操作却使用原始的 64 位大小,从而引发堆缓冲区溢出。攻击者若能控制 OCI 注册表,便可构造特定的增量流,在 flatpak 安装或更新时触发此漏洞,在 32 位系统上 potentially 实现代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96279 | 6.5 MEDIUM | Flatpak: flatpak: path traversal issue in oci archive extraction via hardlinks |
| CVE-2026-96281 | 6.2 MEDIUM | Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system app |
| CVE-2026-96283 | 3.3 LOW | Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoi |
| CVE-2026-96282 | 3.1 LOW | Flatpak: flatpak: extension metadata path traversal file existence oracle |
| CVE-2026-96284 | 2.5 LOW | Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci syml |
No comments yet