PT-2026-31025 · Flatpak+1 · Flatpak+1

CVE-2026-34079

·

Published

2026-04-07

·

Updated

2026-09-10

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Flatpak versions prior to 1.16.4
Description Flatpak, a Linux application sandboxing and distribution framework, contained a flaw where the caching mechanism for ld.so did not adequately verify that an application-controlled path to an outdated cache resided within the cache directory. This allowed Flatpak applications to delete arbitrary files on the host system.
Recommendations Update to Flatpak version 1.16.4 or later.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:21755
ALSA-2026:21756
ALSA-2026:21757
BDU:2026-05832
CVE-2026-34079
GHSA-P29X-R292-46PP
OESA-2026-2590
OESA-2026-2591
OESA-2026-2709
OESA-2026-2710
OPENSUSE-SU-2026:10541-1
RHSA-2026:23417
RHSA-2026:23418
RHSA-2026:23419
RHSA-2026:23420
RHSA-2026:25068
RHSA-2026:25381
SUSE-SU-2026:1511-1
SUSE-SU-2026:1541-1
SUSE-SU-2026:1600-1
SUSE-SU-2026:1713-1
USN-8741-1

Affected Products

Flatpak
Rocky Linux