Flatpak 1.18.4 Fixes Root-Context Host File Overwrite and Deletion Flaws


Flatpak 1.18.4, released September 28, 2026, fixes two high-impact path-traversal vulnerabilities that can let a malicious Flatpak application damage files on the host while it is installed or upgraded. CVE-2026-97024 can empty certain host files or replace resolv.conf with a symlink, while CVE-2026-97023 can delete an attacker-chosen host file. For system-wide Flatpak installations, the vulnerable deployment operations run as root.

Upstream lists 1.18.4 as the patched release for both issues. The release also fixes four additional Flatpak CVEs involving OCI authentication-token exposure, temporary repository permissions, desktop and D-Bus service metadata, and process-group signaling. Linux administrators should treat 1.18.4 as one cumulative security update covering the full batch.

The trigger is installation or upgrade of a malicious Flatpak app. This makes repository trust and installation scope important controls: system-wide deployment raises the consequence because the affected filesystem operations execute with root privileges.

CVE-2026-97024 can damage host configuration files

CVE-2026-97024 affects Flatpak's handling of the app deployment files/etc directory. A malicious application can use path traversal so deployment reaches host files outside the intended directory.

The published advisory describes host files including passwd, group, machine-id and resolv.conf. The vulnerable operation can empty affected files; resolv.conf can also be replaced with a symlink to /run/host/monitor/resolv.conf. The consequence is primarily host integrity and availability damage, including the possibility of breaking account, identity or name-resolution configuration.

Red Hat's CNA record assigns CVE-2026-97024 a 7.1 High CVSS 3.1 score. The attack requires a user to install or upgrade the malicious application. Flatpak's 1.18.4 release notes identify the fix and add further symlink-traversal hardening around deployment paths.

CVE-2026-97023 permits attacker-chosen file deletion

CVE-2026-97023 is a related path-traversal flaw in Flatpak's handling of export/bin during deployment. Upstream says a malicious Flatpak application can arrange for an attacker-chosen file outside the deployment directory to be deleted when the app is upgraded.

GitHub's Flatpak advisory rates the issue High at 7.1 under CVSS 4.0, lists versions before 1.18.4 as affected, and identifies 1.18.4 or later as patched. The system-wide installation path performs the deletion as root.

Upstream's workaround is to avoid Flatpak applications from untrusted publishers, particularly for system-wide installations. Installing the fixed package is the durable remediation.

Flatpak 1.18.4 fixes six newly listed CVEs

The release contains a broader security batch:

CVE Upstream-described issue Operational impact
CVE-2026-97024 Path traversal in deployment files/etc handling Host files can be emptied; resolv.conf can be replaced with a symlink
CVE-2026-97023 Path traversal in export/bin handling Attacker-chosen host file deletion
CVE-2026-97025 OCI authentication token exposed to other local users Credential exposure on authenticated OCI pulls
CVE-2026-97026 Permissions on /var/tmp/flatpak-cache-* temporary repositories Local access-control weakness
CVE-2026-97027 Unsafe fields in .desktop and D-Bus .service files Denial of service or unintended host-service interaction
CVE-2026-97029 App can signal a process group containing a parent outside the app Desktop-environment denial of service

Flatpak 1.18.4 also updates its bundled xdg-dbus-proxy subproject to 0.1.9 for CVE-2026-93676 and CVE-2026-94422.

Distribution package versions can differ from upstream

Administrators should check the security package supplied by their Linux distribution instead of requiring the package version string to equal upstream 1.18.4. Distributions can backport the fixes to an older maintained branch.

Debian's security tracker provides a concrete example. It records Debian 13 trixie Flatpak 1.16.6-1~deb13u3 as fixed for CVE-2026-97023 and CVE-2026-97024, while Debian unstable records 1.18.4-1 as fixed. At the time of checking, Debian 12 bookworm remains listed as vulnerable in the tracker for these two CVEs.

For managed Linux fleets, the practical check is two-part: identify hosts with Flatpak installed, then compare their package state with the distribution's security advisory or tracker. Systems that permit system-wide installation of Flatpaks from third-party sources deserve the highest remediation priority because the vulnerable deployment operations can run as root.

Bottom line

Flatpak 1.18.4 closes a security boundary at installation time. CVE-2026-97024 can damage important host configuration files and CVE-2026-97023 can delete an attacker-chosen host file; system-wide installs execute the affected operations with root authority. Upstream users should move to 1.18.4 or later, while distribution users should install the vendor package carrying the backported fixes.

The broader six-CVE batch makes the update relevant even on systems where administrators tightly control Flatpak sources. Repository trust reduces exposure to the two malicious-app deployment paths, while the fixed package removes the vulnerable filesystem behavior.

Sources