CVE-2026-96280

HIGH CVSS 3.1: 7.5
Updated Sep 28, 2026
Red Hat
Parameter Value
CVSS 7.5 (HIGH)
Type CWE-197
Vendor Red Hat
Public PoC No

The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

red hat:red hat enterprise linux 7 red hat:red hat enterprise linux 9 red hat:red hat enterprise linux 10 red hat:red hat enterprise linux 8