Impact
A malicious Flatpak application can exploit a path traversal flaw while deploying files in the /etc directory, causing critical host files such as /etc/passwd, /etc/group, /etc/machine-id, or /etc/resolv.conf to be emptied or replaced with a symbolic link. The vulnerability enables tampering with authentication, networking, or system identification, and is identified as a classic file‑system path traversal weakness (CWE‑61).
Affected Systems
Red Hat Red Enterprise Linux 7, 8, 9, and 10 are affected because Flatpak is bundled with these operating systems, and any system that performs system‑wide Flatpak installations runs with root privileges and is therefore at risk.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity, and the EPSS score is not available, meaning no current exploitation probability is published. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. An attacker only needs to install or upgrade a malicious Flatpak package in a system‑wide context to trigger the privileged write, making it a straightforward local privilege escalation vector.
OpenCVE Enrichment
Debian DSA