CVE-2026-96807
EUVD-2026-8542323.09.2026, 17:17
In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. The filenames and content are not attacker controlled, making this hard to exploit.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| flatpak | flatpak | 𝑥 < 1.18.1 | CNA |
Debian Releases