CVE-2026-96283: Red Hat Enterprise Linux 10

Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.

By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.

Affected products

Published 2026-09-27. Last modified 2026-09-29.