(RHSA-2026:25381) Important: flatpak security update
摘要
Important: flatpak security update
正文
Overview Updated Packages Important: flatpak security update Security Advisory: Important Identify and remediate systems affected by this advisory. View affected systems An update for flatpak is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Security Fix(es): flatpak: Flatpak: Arbitrary code execution via crafted symlinks in sandbox-expose options (CVE-2026-34078) flatpak: Flatpak: Arbitrary file deletion on host via improper cache file path validation (CVE-2026-34079) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64 Red Hat Enterprise Linux Server - AUS 8.6 x86_64 BZ - 2456276 - CVE-2026-34078 flatpak: Flatpak: Arbitrary code execution via crafted symlinks in sandbox-expose options BZ - 2456284 - CVE-2026-34079 flatpak: Flatpak: Arbitrary file deletion on host via improper cache file path validation CVE-2026-34078 CVE-2026-34079 https://access.redhat.com/security/updates/classification/#important The Red Hat security contact is [email protected] . More contact details at https://access.redhat.com/security/team/contact/ .
标签
- Important
- Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension
- Red Hat Enterprise Linux Server - AUS
扩展字段
{
"cves": [
"CVE-2026-34078",
"CVE-2026-34079"
],
"product_names": [
"Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension",
"Red Hat Enterprise Linux Server - AUS"
],
"update_date": [
"2026-06-11T19:14:22Z"
]
}