Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34078

Опубликовано: 07 апр. 2026
Источник: redhat
CVSS3: 9

Описание

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

A flaw was found in Flatpak, a Linux application sandboxing and distribution framework. A malicious application could exploit this by using specially crafted symlinks within the sandbox-expose options of the Flatpak portal. This allows the application to access arbitrary host files and potentially achieve code execution on the host system, bypassing the intended security sandbox.

Отчет

This Important flaw in Flatpak allows a malicious Flatpak application to escape its sandbox and achieve arbitrary code execution on the host system. By exploiting specially crafted symlinks within the sandbox-expose options, the integrity of the Flatpak sandboxing mechanism, a critical security feature in Red Hat environments, is compromised.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2456276flatpak: Flatpak: Arbitrary code execution via crafted symlinks in sandbox-expose options

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 10
ubuntu
4 месяца назад

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

CVSS3: 10
nvd
4 месяца назад

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.

CVSS3: 10
debian
4 месяца назад

Flatpak is a Linux application sandboxing and distribution framework. ...

CVSS3: 10
fstec
4 месяца назад

Уязвимость инструмента для управления приложениями и средами Flatpak, связанная с отслеживанием символьных ссылок UNIX, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и выполнить произвольный код

suse-cvrf
3 месяца назад

Security update for flatpak

9 Critical

CVSS3