7.5 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
5 packages
- flatpak-builder
- flatpak-xdg-utils
- flatpak-builder-tools
- kdePackages.flatpak-kcm
- haskellPackages.cabal-flatpak
- @LeSuisse accepted
- @LeSuisse ignored maintainer @getchoo maintainer.ignore
- @LeSuisse restored maintainer @getchoo maintainer.restore
- @LeSuisse published on GitHub
Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems
The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems.
References
Affected products
Matching in nixpkgs
Ignored packages (5)
pkgs.flatpak-builder
Tool to build flatpaks from source
pkgs.flatpak-xdg-utils
Commandline utilities for use inside Flatpak sandboxes
pkgs.flatpak-builder-tools
Collection of community-contributed scripts to assist with building applications using Flatpak Builder
-
nixos-unstable -
- nixos-unstable-small 0-unstable-2026-09-12
pkgs.kdePackages.flatpak-kcm
Flatpak Permissions Management KCM
pkgs.haskellPackages.cabal-flatpak
Generate a FlatPak manifest from a Cabal package description
Package maintainers
-
@getchoo Seth Flynn <getchoo@tuta.io>
6.2 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Physical (P)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Physical (P)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
5 packages
- flatpak-builder
- flatpak-xdg-utils
- flatpak-builder-tools
- kdePackages.flatpak-kcm
- haskellPackages.cabal-flatpak
- @LeSuisse accepted
- @LeSuisse ignored maintainer @getchoo maintainer.ignore
- @LeSuisse published on GitHub
Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes
On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.
References
Affected products
Matching in nixpkgs
Ignored packages (5)
pkgs.flatpak-builder
Tool to build flatpaks from source
pkgs.flatpak-xdg-utils
Commandline utilities for use inside Flatpak sandboxes
pkgs.flatpak-builder-tools
Collection of community-contributed scripts to assist with building applications using Flatpak Builder
-
nixos-unstable -
- nixos-unstable-small 0-unstable-2026-09-12
pkgs.kdePackages.flatpak-kcm
Flatpak Permissions Management KCM
pkgs.haskellPackages.cabal-flatpak
Generate a FlatPak manifest from a Cabal package description
Package maintainers
Ignored maintainers (1)
-
@getchoo Seth Flynn <getchoo@tuta.io>
3.1 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
5 packages
- flatpak-builder
- flatpak-xdg-utils
- flatpak-builder-tools
- kdePackages.flatpak-kcm
- haskellPackages.cabal-flatpak
- @LeSuisse ignored maintainer @getchoo maintainer.ignore
- @LeSuisse accepted
- @LeSuisse published on GitHub
Flatpak: flatpak: extension metadata path traversal file existence oracle
A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the extension. Additionally, unvalidated extension metadata can cause extension content to be mounted at unintended locations inside the sandbox.
References
Affected products
Matching in nixpkgs
Ignored packages (5)
pkgs.flatpak-builder
Tool to build flatpaks from source
pkgs.flatpak-xdg-utils
Commandline utilities for use inside Flatpak sandboxes
pkgs.flatpak-builder-tools
Collection of community-contributed scripts to assist with building applications using Flatpak Builder
-
nixos-unstable -
- nixos-unstable-small 0-unstable-2026-09-12
pkgs.kdePackages.flatpak-kcm
Flatpak Permissions Management KCM
pkgs.haskellPackages.cabal-flatpak
Generate a FlatPak manifest from a Cabal package description
Package maintainers
Ignored maintainers (1)
-
@getchoo Seth Flynn <getchoo@tuta.io>