Skip to content
Red HatCVE-2026-96275

Red Hat Enterprise Linux: path traversal

High8.8CVE-2026-96275 · Published Sep 23, 2026 · updated Sep 25, 2026

A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat OpenShift Container Platform 4: path traversal
High7.5Sep 23
Red Hat OpenShift Container Platform 4: attacker could send requests
High7.2Sep 23
Red Hat librsvg.: use after free
High7.8Sep 23
Red Hat: argument injection
Medium6.6Sep 23
A flaw was found in the Ansible Automation Platform automation controller
High7.2Sep 23
Red Hat: incomplete denylist
High7.1Sep 23

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.