CVE-2026-34078

high
Published 2026-05-28 ยท Modified 2026-05-28
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.0

Description

RHSA-2026:21756: flatpak security update (Important)

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description flatpak: Flatpak: Arbitrary code execution via crafted symlinks in sandbox-expose options Red Hat statement This Important flaw in Flatpak allows a malicious Flatpak application to escape its sandbox and achieve arbitrary code execution on the host system. By exploiting specially crafted symlinks within the `sandbox-expose` options, the integrity of the Flatpak sandboxing mechanism, aโ€ฆ

Description

flatpak: Flatpak: Arbitrary code execution via crafted symlinks in sandbox-expose options

Red Hat statement

This Important flaw in Flatpak allows a malicious Flatpak application to escape its sandbox and achieve arbitrary code execution on the host system. By exploiting specially crafted symlinks within the `sandbox-expose` options, the integrity of the Flatpak sandboxing mechanism, a critical security feature in Red Hat environments, is compromised.

CVSS v3: 9.0 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)

Package state

ProductPackageState
Red Hat Enterprise Linux 10flatpakAffected
Red Hat Enterprise Linux 7flatpakAffected
Red Hat Enterprise Linux 8flatpakAffected
Red Hat Enterprise Linux 9flatpakAffected

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 9Affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Fixed 1.16.6-1~deb13u1
sid Fixed 1.16.4-1
forky Fixed 1.16.4-1
bullseye Affected โ€”
bookworm Fixed 1.14.10-1~deb12u2
almalinux AlmaLinux Fixed 2 releases
VersionStatusFixed in
9 Fixed flatpak-libs-1.12.9-4.el9_8.1.i686.rpm
8 Fixed flatpak-session-helper-1.12.9-4.el8_10.i686.rpm
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.