Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. This vulnerability is fixed in 1.16.4.
References
| Link | Resource |
|---|---|
| https://github.com/flatpak/flatpak/security/advisories/GHSA-p29x-r292-46pp | Vendor Advisory |
Configurations
History
17 Apr 2026, 20:26
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Flatpak
Flatpak flatpak |
|
| References | () https://github.com/flatpak/flatpak/security/advisories/GHSA-p29x-r292-46pp - Vendor Advisory | |
| CPE | cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:* |
10 Apr 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
07 Apr 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-07 22:16
Updated : 2026-06-17 10:38
NVD link : CVE-2026-34079
Mitre link : CVE-2026-34079
CVE.ORG link : CVE-2026-34079
JSON object : View
Products Affected
flatpak
- flatpak
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
