Skip to content
Red HatCVE-2026-97023

Red Hat Enterprise Linux: path traversal

High7.1CVE-2026-97023 · Published Sep 28, 2026 · updated Sep 29, 2026

A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations, the deletion is performed as root.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux: denial of service
Low3.6Sep 28
Flatpak writes the OCI repository authentication token with world-readable...
Low3.2Sep 28
Red Hat Enterprise Linux: denial of service
Low3.9Sep 28
Red Hat GCC.: use after free
High7.0Sep 28
A flaw was found in the StreamsHub Console for Apache Kafka
Medium6.5Sep 28
Red Hat kube-compare.: remote code execution
High7.1Sep 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.