Flatpak 在导出应用程序的桌面入口(.desktop)和 D-Bus 服务(.service)文件时,会未经修改地透传任意厂商扩展键,而不是对其进行白名单验证。恶意 Flatpak 应用可以利用此漏洞导致拒绝服务(例如强制应用程序重启循环),或影响宿主机上的 D-Bus/systemd 激活行为,从而突破沙箱所允许的操作范围。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101292 | 8.2 HIGH | Artemis-core-client: unsafe reflection in apache activemq artemis federation message deser |
| CVE-2026-86330 | 7.2 HIGH | Noobaa-core: noobaa-core: os command injection in cluster_internal_api.set_hostname_intern |
| CVE-2026-97023 | 7.1 HIGH | Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy dir |
| CVE-2026-87114 | 7.1 HIGH | Kube-compare: container:// reference extraction runs the image entrypoint and silently esc |
| CVE-2026-102010 | 7.0 HIGH | Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in bina |
| CVE-2026-96740 | 6.5 MEDIUM | Streamshub/console: console-operator: streams for apache kafka console: unfiltered kafka c |
| CVE-2026-97026 | 3.9 LOW | Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path |
| CVE-2026-101333 | 3.7 LOW | Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on brok |
| CVE-2026-97025 | 3.2 LOW | Flatpak: flatpak: world-readable oci authentication token in system-helper cache path |
No comments yet