Understanding and Defending Against CVE-2026-96280: A Heap Buffer Overflow in Flatpak
CVE-2026-96280 is a heap buffer overflow vulnerability in the OCI delta stream parser used by Flatpak, a system for building, distributing, and running sandboxed desktop applications on Linux. This vulnerability allows an attacker controlling an OCI registry to potentially achieve code execution on 32-bit systems during a flatpak install or update. The vulnerability has a CVSS score of 7.5, indicating a high severity. Understanding this vulnerability is crucial for defenders to protect their Linux systems.