medium · CVSS v3 4
CVE-2026-96807
In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regener…
Description
In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. The filenames and content are not attacker controlled, making this hard to exploit.
Scores
- Severity
- medium
- CVSS v2
- 2.6
- CVSS v3
- 4
- CVSS v4
- —
- EPSS
- —