Skip to content
Red HatCVE-2026-96279

Red Hat Enterprise Linux: link following

Medium6.5CVE-2026-96279 · Published Sep 27, 2026

A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide installs running as root, this includes sensitive files such as /etc/shadow.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux: link following
Low2.5Sep 27
Red Hat Enterprise Linux: link following
Low3.1Sep 27
Red Hat Enterprise Linux: missing authorization
Low3.3Sep 27
Red Hat Enterprise Linux: code execution
High7.5Sep 27
Red Hat Enterprise Linux: improper access control
Medium6.2Sep 27
Red Hat QEMU: use after free
High8.8Sep 25

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.