Back Redpacketsecurity CVE Alert: CVE-2026-96280 – Red Hat
The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems.
**Risk verdict:** High-impact but conditional: prioritise systems that use OCI-based Flatpak remotes on 32-bit platforms; the supplied data has no KEV, SSVC, PoC or EPSS indicators, so active exploitation urgency cannot be confirmed.
**Why this matters:** A successful attack could compromise the machine running the install or update, with potential effects on data confidentiality, integrity and availability. Realistic targets include developer or user endpoints and build hosts that fetch applications from registries an attacker can control or compromise.
**Most likely attack path:** An attacker must influence the OCI registry content, then rely on an administrator or user to install or update from that remote. Network reachability and no required privileges lower some barriers, but the high attack complexity and required user interaction constrain exploitation; scope is unchanged, so the expected impact is on the affected host rather than automatic lateral movement.
**Who is most exposed:** Focus on 32-bit systems using Flatpak with OCI remotes, especially workstations and build environments that routinely install or update apps. Systems using the default OSTree transport are not exposed to this path.
Review Flatpak install/update history for OCI remotes and unexpected applications.
Correlate registry connections with Flatpak activity, especially to unfamiliar hosts.
Investigate Flatpak crashes or memory-corruption alerts during OCI operations.
Mitigation and prioritisation
Apply the vendor’s fixed package update; confirm the fix status before scheduling.
Until patched, restrict OCI remotes to trusted registries; prefer the default OSTree transport where suitable.
Prioritise exposed 32-bit hosts, with change control and validation of app installs after updating.
Check KEV, SSVC, PoC and EPSS status before finalising urgency.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
