Red Hat · Red Hat · CVE-2026-96280
**Name of the Vulnerable Software and Affected Versions**
Red Hat Enterprise Linux (affected versions not specified)
**Description**
The OCI delta stream parser reads sizes as `guint64` but passes them to GLib I/O and allocation functions that expect `gsize`. On 32-bit systems, `gsize` is 32 bits, which causes undersized memory allocations. Because subsequent operations continue to use the original 64-bit size, heap buffer overflows occur. An attacker controlling an OCI registry can craft a malicious delta stream to trigger this issue during a flatpak install or update, potentially leading to arbitrary code execution on 32-bit systems.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.