Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-96276

Источник: debian

Описание

[GHSA-8qxj-x646-phcm]

Пакеты

ПакетСтатусВерсия исправленияРелизТип
flatpakfixed1.18.1-1package

Примечания

  • https://github.com/flatpak/flatpak/security/advisories/GHSA-8qxj-x646-phcm

  • Fixed by: https://github.com/flatpak/flatpak/commit/c42326c74d63e550d874312be0c7a800cf5fc39f (1.18.1)

  • Fixed by: https://github.com/flatpak/flatpak/commit/12a30ecb422b1e1246cb2d9af60c14ef7b8f22a4 (1.18.1)

  • Fixed by: https://github.com/flatpak/flatpak/commit/71f28c42ffff7bfd132fbee1ebc50ab0d08de2d3 (1.18.1)

  • Fixed by: https://github.com/flatpak/flatpak/commit/fb8ae524738e0a0097a6d64bfcda71552174b7fb (branch flatpak-1.16.x)

  • Fixed by: https://github.com/flatpak/flatpak/commit/c0a109aa4f861f557aed60c42d0ee64d2c3a943c (branch flatpak-1.16.x)

  • Fixed by: https://github.com/flatpak/flatpak/commit/619e75e7e453697b3f1d50d84e116e4df3d15df6 (branch flatpak-1.16.x)

  • Additional requirement: https://github.com/flatpak/flatpak/commit/3d43a0f5fa602cc3edc557d8ab835030140792b1 (branch flatpak-1.16.x)

  • Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 дня назад

security update

redhat
около 2 месяцев назад

If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal.

CVSS3: 9.8
nvd
2 дня назад

If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal.