Bug 2456284 (CVE-2026-34079) - CVE-2026-34079 flatpak: Flatpak: Arbitrary file deletion on host via improper cache file path validation
Summary: CVE-2026-34079 flatpak: Flatpak: Arbitrary file deletion on host via improper...
Keywords:
Status: NEW
Alias: CVE-2026-34079
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2456394 2456395
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-07 22:02 UTC by OSIDB Bzimport
Modified: 2026-04-08 09:18 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-04-07 22:02:01 UTC
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps  to delete arbitrary files on the host. This vulnerability is fixed in 1.16.4.


Note You need to log in before you can comment on or make changes to this bug.