Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-34079

Опубликовано: 07 апр. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. This vulnerability is fixed in 1.16.4.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:*
Версия до 1.16.4 (исключая)

EPSS

Процентиль: 24%
0.00323
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. This vulnerability is fixed in 1.16.4.

CVSS3: 6.7
redhat
4 месяца назад

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. This vulnerability is fixed in 1.16.4.

CVSS3: 7.5
debian
4 месяца назад

Flatpak is a Linux application sandboxing and distribution framework. ...

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость инструмента для управления приложениями и средами Flatpak, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю получить доступ на удаление произвольных файлов

suse-cvrf
3 месяца назад

Security update for flatpak

EPSS

Процентиль: 24%
0.00323
Низкий

7.5 High

CVSS3

Дефекты

CWE-22