Back

LOW

Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path

Published Sep 28, 2026

Description

Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runtimes, potentially causing installation failures (denial of service); tampered content would fail signature/digest verification rather than being trusted.

Affected products

Remediation

Vendor solution

Set a umask that does not allow other users to write to the cache directory, for example: umask 022.

Note that a umask that does not allow read/exec access by all (for example 027 or 077) will prevent the flatpak-system-helper from reading the temporary directory directly, resulting in falling back to copying the repository inefficiently, with a warning.

Red Hat statement

Red Hat estimates the CVSSv3.1 vector of CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L from provided CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N. Requires user interaction and scope remains unchanged.

Red Hat mitigation

Set a umask that does not allow other users to write to the cache directory, for example: umask 022. Note that a umask that does not allow read/exec access by all (for example 027 or 077) will prevent the flatpak-system-helper from reading the temporary directory directly, resulting in falling back to copying the repository inefficiently, with a warning.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 28, 2026
Updated Sep 30, 2026
Reserved Sep 23, 2026
CISA Vulnrichment
Updated Sep 30, 2026
NVD
Status Received
Modified Sep 28, 2026
Red Hat
Severity Low
Public date Sep 28, 2026