Skip to content
Red HatCVE-2026-97026

Red Hat Enterprise Linux: denial of service

Low3.9CVE-2026-97026 · Published Sep 28, 2026 · updated Sep 30, 2026

Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runtimes, potentially causing installation failures (denial of service); tampered content would fail signature/digest verification rather than being trusted.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux: denial of service
Low3.6Sep 28
Flatpak writes the OCI repository authentication token with world-readable...
Low3.2Sep 28
Red Hat Enterprise Linux: path traversal
High7.1Sep 28
Red Hat GCC.: use after free
High7.0Sep 28
A flaw was found in the StreamsHub Console for Apache Kafka
Medium6.5Sep 28
Red Hat kube-compare.: remote code execution
High7.1Sep 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.