CVE 2026 96280
The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems.
Red Hat estimates the CVSSv3.1 vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H.
The malicious stream is served over the network (AV:N), and the attacker needs only control over the OCI registry content (PR:N). The OCI delta stream parser reads sizes as a 64-bit guint64 but passes them to GLib I/O and allocation functions expecting gsize; on 32-bit systems gsize is only 32 bits wide, so the value is silently truncated, producing an undersized allocation while later operations still use the original 64-bit size, leading to a heap buffer overflow. This overflow only manifests on 32-bit targets — on 64-bit systems gsize and guint64 are the same width and truncation does not occur, so exploitability depends on a target configuration outside the attacker's control (AC:H). Meaningful user interaction is required (UI:R).
The vulnerable and impacted components remain within the same flatpak client/helper security authority (S:U). Because this is a heap buffer overflow with a stated path to code execution in the Flatpak client process, a successful exploit is treated as a full compromise of that process's privileges (C:H/I:H/A:H).
Only install applications from trusted OCI registries. Flatpak remotes using the default OSTree transport are not affected.
Bugzilla 2539419 : flatpak: flatpak: Buffer overflow in OCI delta stream path names on 32-bit systems
CWE-197 : Numeric Truncation Error
Common Vulnerability Scoring System (CVSS) Score Details
Info alert: Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications ).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
cve.org: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Understanding the Weakness (CWE)
Technical Impact: Modify Memory
The true value of the data is lost and corrupted data is used.
Upstream acknowledges Sebastian Wick as the original reporter.
Frequently Asked Questions
"Under investigation" doesn't necessarily mean that the product is affected by this vulnerability. It only means that our Analysis Team is still working on determining whether the product is affected and how it is affected.
The term 'Affected' means that our Analysis team has determined that this product, such as Red Hat Enterprise Linux 8 or OpenShift Container Platform 4, is affected by this vulnerability and a fix may be released to address this issue in the near future. This includes all minor releases of this product unless noted otherwise in the Statement text.
Upgrade to a supported product version that includes a fix for this vulnerability (recommended).
Apply a mitigation (if one exists).
Customers with the Technical Account Manager (TAM) RHEL Security Select Add-on can review this CVE directly with their TAM.
Apply a mitigation (if one exists).
Red Hat Engineering focuses on addressing high-priority issues based on the impact and product lifecycle expectations. Therefore, lower-priority issues will not receive immediate fixes.
Customers with the technical account manager (TAM) RHEL Security Select Add-on can review this CVE directly with their TAM.
Not sure what something means? Check out our Security Glossary .
For clarification or corrections, please Red Hat Product Security .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
