Back

HIGH

Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems

Published Sep 27, 2026

Description

The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems.

Affected products

Remediation

Vendor solution

Only install applications from trusted OCI registries. Flatpak remotes using the default OSTree transport are not affected.

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 27, 2026
Updated Sep 29, 2026
Reserved Sep 22, 2026
CISA Vulnrichment
Updated Sep 29, 2026
NVD
Status Received
Modified Sep 27, 2026
Red Hat
Severity n/a
Public date n/a