Skip to content
Red HatCVE-2026-96280

Red Hat Enterprise Linux: code execution

High7.5CVE-2026-96280 · Published Sep 27, 2026

The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux: link following
Low2.5Sep 27
Red Hat Enterprise Linux: link following
Low3.1Sep 27
Red Hat Enterprise Linux: missing authorization
Low3.3Sep 27
Red Hat Enterprise Linux: improper access control
Medium6.2Sep 27
Red Hat Enterprise Linux: link following
Medium6.5Sep 27
Red Hat QEMU: use after free
High8.8Sep 25

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.