ZeroHour
Product

Flatpak

1 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

USN-8779-2: Bubblewrap regression

Ubuntu issued USN-8779-2 reverting a Bubblewrap symlink fix for CVE-2026-87766 that caused a regression preventing some Flatpak apps from launching.

USN-8779-2 reverts the CVE-2026-87766 fix from USN-8779-1 because it introduced a regression in symlink resolution that stopped certain Flatpak applications from launching; a complete fix is still pending. The original advisory detailed CVE-2019-12439, where mishandled temporary directories could let a local attacker cause denial of service or execute arbitrary code on Ubuntu 18.04 LTS only, plus improper symlink handling during sandbox setup with similar local impact.

Ubuntu Security Noticesupdated · 5h agofirst · 17h agoAdvisory 19 sourcesCVE-2026-87766CVE-2019-12439

USN-8741-1: Flatpak vulnerabilities

Ubuntu patched two Flatpak flaws, including a sandbox escape via app-controlled symlinks allowing host code execution (CVE-2026-34078).

Ubuntu security notice USN-8741-1 fixes two Flatpak vulnerabilities in Ubuntu 20.04 LTS, 22.04 LTS, and 24.04 LTS. CVE-2026-34078 stems from improper path validation in sandbox-expose options, letting a malicious or compromised Flatpak app use app-controlled symlinks to access arbitrary host files and gain code execution in the host context. CVE-2026-34079 involves improper path validation when removing outdated ld.so cache files, allowing a compromised app to delete arbitrary files on the host.

Related CVEs

  • Flatpak is a Linux application sandboxing and distribution framework.
    Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.
    · flatpak flatpak
  • Symlink-following sandbox escape (arbitrary file write) in bubblewrap before 0.12.0
    CVE-2026-87766 is a symlink-following flaw (CWE-59) in bubblewrap, the Linux sandboxing tool: during sandbox setup, when bubblewrap creates files or directories under the new root, it can follow a parent symlink through /oldroot onto the host filesystem. The attack is triggered locally (CVSS AV:L/PR:L) before the sandboxed process starts, by an attacker with low privileges who can influence the sandbox setup, for example a sandboxed application being launched or a nested-bwrap scenario, so that writes land at attacker-chosen paths outside the sandbox. The attacker gains the ability to create or overwrite files and directories on the host with the privileges of the user launching the sandbox, breaking the sandbox boundary (CVSS scope-changed, S:C, with high confidentiality, integrity and availability impact; 8.8 High). Any Linux system running bubblewrap versions prior to 0.12.0 is affected, notably desktop distributions where bubblewrap is pulled in as a Flatpak dependency and other tooling that invokes bwrap for sandboxing. No exploitation is currently known: the flaw is not in CISA KEV, no public proof-of-concept is known, and the issue (GHSA-pxhw-h44j-8pfx, assigned by Red Hat) is fixed upstream in bubblewrap 0.12.0.
    · bubblewrap project (freedesktop.org) bubblewrap all versions prior to 0.12.0mass
  • Flatpak is a Linux application sandboxing and distribution framework.
    Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. This vulnerability is fixed in 1.16.4.
    · flatpak flatpak
  • bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point.
    bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.
    · projectatomic bubblewrap

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.