Nixpkgs security tracker

Try the new UI
Login with GitHub

Details of issue NIXPKGS-2026-2785

NIXPKGS-2026-2785
published 10 hours ago
flatpak: security issues < 1.18.1
Permalink CVE-2026-96280
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • flatpak-builder
    • flatpak-xdg-utils
    • flatpak-builder-tools
    • kdePackages.flatpak-kcm
    • haskellPackages.cabal-flatpak
  • @LeSuisse accepted
  • @LeSuisse ignored maintainer @getchoo maintainer.ignore
  • @LeSuisse restored maintainer @getchoo maintainer.restore
  • @LeSuisse published on GitHub
Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems

The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems.

Affected products

flatpak

Matching in nixpkgs

pkgs.flatpak

Linux application sandboxing and distribution framework

  • nixos-unstable -
  • nixos-26.05 -
Ignored packages (5)

pkgs.flatpak-builder

Tool to build flatpaks from source

  • nixos-unstable -
  • nixos-26.05 -
    • nixos-26.05-small 1.4.4

pkgs.flatpak-xdg-utils

Commandline utilities for use inside Flatpak sandboxes

  • nixos-unstable -
    • nixos-unstable-small 1.0.6
  • nixos-26.05 -
    • nixos-26.05-small 1.0.6

Package maintainers

Permalink CVE-2026-96281
6.2 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Physical (P)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Physical (P)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • flatpak-builder
    • flatpak-xdg-utils
    • flatpak-builder-tools
    • kdePackages.flatpak-kcm
    • haskellPackages.cabal-flatpak
  • @LeSuisse accepted
  • @LeSuisse ignored maintainer @getchoo maintainer.ignore
  • @LeSuisse published on GitHub
Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes

On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.

Affected products

flatpak

Matching in nixpkgs

pkgs.flatpak

Linux application sandboxing and distribution framework

  • nixos-unstable -
  • nixos-26.05 -
Ignored packages (5)

pkgs.flatpak-builder

Tool to build flatpaks from source

  • nixos-unstable -
  • nixos-26.05 -
    • nixos-26.05-small 1.4.4

pkgs.flatpak-xdg-utils

Commandline utilities for use inside Flatpak sandboxes

  • nixos-unstable -
    • nixos-unstable-small 1.0.6
  • nixos-26.05 -
    • nixos-26.05-small 1.0.6

Package maintainers

Ignored maintainers (1)
Permalink CVE-2026-96282
3.1 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    5 packages
    • flatpak-builder
    • flatpak-xdg-utils
    • flatpak-builder-tools
    • kdePackages.flatpak-kcm
    • haskellPackages.cabal-flatpak
  • @LeSuisse ignored maintainer @getchoo maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Flatpak: flatpak: extension metadata path traversal file existence oracle

A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the extension. Additionally, unvalidated extension metadata can cause extension content to be mounted at unintended locations inside the sandbox.

Affected products

flatpak

Matching in nixpkgs

pkgs.flatpak

Linux application sandboxing and distribution framework

  • nixos-unstable -
  • nixos-26.05 -
Ignored packages (5)

pkgs.flatpak-builder

Tool to build flatpaks from source

  • nixos-unstable -
  • nixos-26.05 -
    • nixos-26.05-small 1.4.4

pkgs.flatpak-xdg-utils

Commandline utilities for use inside Flatpak sandboxes

  • nixos-unstable -
    • nixos-unstable-small 1.0.6
  • nixos-26.05 -
    • nixos-26.05-small 1.0.6

Package maintainers

Ignored maintainers (1)