By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No known mitigation other than updating.
References
History
Sun, 27 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
Sun, 27 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped. | |
| Title | Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoing pull | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-27T22:04:48.485Z
Reserved: 2026-09-22T20:44:08.159Z
Link: CVE-2026-96283
No data.
Status : Received
Published: 2026-09-27T22:17:06.557
Modified: 2026-09-27T22:17:06.557
Link: CVE-2026-96283
No data.
OpenCVE Enrichment
No data.
Weaknesses