CVE-2026-96284: Red Hat Enterprise Linux 10
Low severity, CVSS 2.5. EPSS: 0.1% chance of exploitation in the next 30 days.
A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
Published 2026-09-27. Last modified 2026-09-29.