Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-34079

Опубликовано: 07 апр. 2026
Источник: debian
EPSS Низкий

Описание

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. This vulnerability is fixed in 1.16.4.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
flatpakfixed1.16.4-1package

Примечания

  • https://github.com/flatpak/flatpak/security/advisories/GHSA-p29x-r292-46pp

EPSS

Процентиль: 25%
0.00323
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. This vulnerability is fixed in 1.16.4.

CVSS3: 6.7
redhat
4 месяца назад

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. This vulnerability is fixed in 1.16.4.

CVSS3: 7.5
nvd
4 месяца назад

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. This vulnerability is fixed in 1.16.4.

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость инструмента для управления приложениями и средами Flatpak, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю получить доступ на удаление произвольных файлов

suse-cvrf
3 месяца назад

Security update for flatpak

EPSS

Процентиль: 25%
0.00323
Низкий