Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4505 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-96280EXPLOITED
red hat · red hat enterprise linux

Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems

Description

The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

References

  • https://access.redhat.com/security/cve/CVE-2026-96280(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2539419(issue-tracking, x_refsource_REDHAT)
  • https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc

Related News (1 articles)

Tier C
VulDB7h ago
CVE-2026-96280 | Red Hat Enterprise Linux OCI delta stream parser heap-based overflow
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-197
PublishedSep 27, 2026
Last enriched6h ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score45
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-96281EXP
Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes
Trending: 42
LOWCVE-2026-96284EXP
Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci symlink following
Trending: 40
NONECVE-2026-97185EXP
Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file
Trending: 36
NONECVE-2026-88924EXP
Gvfs: gvfs-admin socket ownership race permits local root
Trending: 36
CRITICALCVE-2026-96276EXP
Flatpak: flatpak: arbitrary write in host context via flatpak build-init
Trending: 33

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 27, 2026
Discovered by ZDM
Sep 27, 2026
Actively Exploited
Sep 27, 2026
Exploit Available
Sep 27, 2026