Description
By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.
No analysis available yet.
Remediation
Vendor Workaround
No known mitigation other than updating.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sun, 27 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
Sun, 27 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped. | |
| Title | Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoing pull | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-27T22:04:48.485Z
Reserved: 2026-09-22T20:44:08.159Z
Link: CVE-2026-96283
No data.
Status : Received
Published: 2026-09-27T22:17:06.557
Modified: 2026-09-27T22:17:06.557
Link: CVE-2026-96283
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-862
Missing Authorization