Flatpak 在用户缓存目录下创建具有世界可写权限(权限模式 0777)的临时子仓库目录。在具有宽松 umask 设置的多用户系统上,其他本地用户可能能够读取或修改在安装应用程序或运行时期间使用的临时目录,从而可能导致安装失败(拒绝服务);尽管经过篡改的内容会在签名/摘要验证阶段失败,不会被系统信任。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101292 | 8.2 HIGH | Artemis-core-client: unsafe reflection in apache activemq artemis federation message deser |
| CVE-2026-86330 | 7.2 HIGH | Noobaa-core: noobaa-core: os command injection in cluster_internal_api.set_hostname_intern |
| CVE-2026-97023 | 7.1 HIGH | Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy dir |
| CVE-2026-87114 | 7.1 HIGH | Kube-compare: container:// reference extraction runs the image entrypoint and silently esc |
| CVE-2026-102010 | 7.0 HIGH | Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in bina |
| CVE-2026-96740 | 6.5 MEDIUM | Streamshub/console: console-operator: streams for apache kafka console: unfiltered kafka c |
| CVE-2026-101333 | 3.7 LOW | Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on brok |
| CVE-2026-97027 | 3.6 LOW | Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus |
| CVE-2026-97025 | 3.2 LOW | Flatpak: flatpak: world-readable oci authentication token in system-helper cache path |
No comments yet