Back

LOW

Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus service files

Published Sep 28, 2026

Description

Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, instead of validating against an allowlist. A malicious Flatpak app can use this to cause denial of service (e.g. forced application restart loops) or to influence host D-Bus/systemd activation behavior beyond what the sandbox is intended to permit.

Affected products

Remediation

Vendor solution

Only install applications from trusted sources.

Red Hat statement

Red Hat estimates the CVSSv3.1 vector of CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L. Exploitation requires a victim to install and run a malicious Flatpak application (UI:R), after which the unsanitized exported Desktop Entry / D-Bus Service keys take effect automatically with no additional attacker privileges or access complexity (AV:L, AC:L, PR:N). Because the exported files can influence D-Bus/systemd activation behavior on the host session outside the flatpak sandbox, this is treated as a scope change (S:C). No confidentiality or integrity impact is implied by the primary reported effect (C:N, I:N); the impact is limited to availability, via forced application restart loops or disrupted service activation (A:L).

Red Hat mitigation

Only install applications from trusted sources.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 28, 2026
Updated Sep 29, 2026
Reserved Sep 23, 2026
CISA Vulnrichment
Updated Sep 29, 2026
NVD
Status Received
Modified Sep 28, 2026
Red Hat
Severity Low
Public date Sep 28, 2026