Writeups
Security writeups and technical analyses.
CVE-2026-92162: Arch Path Traversal in the Flatpak System Helper
Technical breakdown of CVE-2026-92162 (GHSA-v2gw-v9h5-9q4x), a path traversal in the Flatpak system helper where an unvalidated arch string lets an active local user make the root helper create directories anywhere on disk, and how it chains into a full root file write.
flatpak / path-traversal / privilege-escalation / dbus / linux / cve
11 min readCVE-2026-18649: Unbounded Memory Growth in GStreamer's RTP Depayloaders
A technical breakdown of a remote, unauthenticated denial of service in GStreamer's H.264 and H.265 RTP depayloaders, where FU-A fragment reassembly had no size limit.
gstreamer / rtp / dos / memory-safety / cve
9 min read