[CLSA-2026:1777890711] flatpak: Fix of CVE-2026-34079
Type:
security
Severity:
Critical
Release date:
2026-05-05 23:30:49 UTC
Description:
- CVE-2026-34079: fix arbitrary host file deletion via app-controlled ld.so cache symlink in flatpak_switch_symlink_and_remove
Updated packages:
  • flatpak-1.0.9-13.el7_9.tuxcare.els4.x86_64.rpm
    sha:29f2c8ac6b3477d36be831c078448363781ab8ae012594331cfa47134e3c5232
  • flatpak-builder-1.0.0-13.el7_9.tuxcare.els4.x86_64.rpm
    sha:9599e311bcdd393f5773f629652e31045de860eaf432fcd7017a5dee52b3da11
  • flatpak-devel-1.0.9-13.el7_9.tuxcare.els4.x86_64.rpm
    sha:9449486630473185b7616a42049d662054e7953494ed7d2716a7b691d3d6ce8e
  • flatpak-libs-1.0.9-13.el7_9.tuxcare.els4.x86_64.rpm
    sha:3f3d6d4919312dfa54fff6e0e39e10b093eace941a57e18ea0a0415286d22dbd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.