Flatpak 以全局可读权限(0644)将 OCI 仓库的认证令牌写入系统辅助程序的缓存目录,这使得在多台用户共享的系统中,其他本地用户可以读取该令牌,并冒充已认证用户访问 OCI 仓库。仅使用 OCI 源的 Flatpak 配置(例如 Fedora 所使用的配置)受影响;使用 libostree 源的 Flatpak 配置(如 Flathub)不受影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101292 | 8.2 HIGH | Artemis-core-client: unsafe reflection in apache activemq artemis federation message deser |
| CVE-2026-86330 | 7.2 HIGH | Noobaa-core: noobaa-core: os command injection in cluster_internal_api.set_hostname_intern |
| CVE-2026-97023 | 7.1 HIGH | Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy dir |
| CVE-2026-87114 | 7.1 HIGH | Kube-compare: container:// reference extraction runs the image entrypoint and silently esc |
| CVE-2026-102010 | 7.0 HIGH | Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in bina |
| CVE-2026-96740 | 6.5 MEDIUM | Streamshub/console: console-operator: streams for apache kafka console: unfiltered kafka c |
| CVE-2026-97026 | 3.9 LOW | Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path |
| CVE-2026-101333 | 3.7 LOW | Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on brok |
| CVE-2026-97027 | 3.6 LOW | Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus |
No comments yet