Linuxsecurity
Critical Flatpak Vulnerabilities Allow Host File Access and Deletion
Article Content
Two critical vulnerabilities in Flatpak, identified as CVE-2026-34078 and CVE-2026-34079, were discovered, allowing malicious applications to access files outside their sandbox or delete arbitrary files on the host system. These vulnerabilities stem from improper path validation in sandbox-expose options and when removing outdated ld.so cache files. Affected systems include Ubuntu 20.04 LTS, 22.04 LTS, and 24.04 LTS. The issues were published on April 7, 2026, and have been addressed through system updates. Users are advised to update their systems to mitigate these risks. The vulnerabilities pose a significant threat as they could lead to unauthorized access and potential code execution on the host. Overall, standard system updates will correct these vulnerabilities.
Key Points: • Flatpak vulnerabilities allow file access and deletion on host systems. • CVE-2026-34078 and CVE-2026-34079 affect Ubuntu 20.04, 22.04, and 24.04 LTS. • Users must update their systems to mitigate these critical vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.