USN-8741-1: Flatpak vulnerabilities
Ubuntu patched two Flatpak flaws, including a sandbox escape via app-controlled symlinks allowing host code execution (CVE-2026-34078).
Ubuntu security notice USN-8741-1 fixes two Flatpak vulnerabilities in Ubuntu 20.04 LTS, 22.04 LTS, and 24.04 LTS. CVE-2026-34078 stems from improper path validation in sandbox-expose options, letting a malicious or compromised Flatpak app use app-controlled symlinks to access arbitrary host files and gain code execution in the host context. CVE-2026-34079 involves improper path validation when removing outdated ld.so cache files, allowing a compromised app to delete arbitrary files on the host.
- CVE-2026-34078: Flatpak sandbox escape enabling host file access and code execution.
- CVE-2026-34079: arbitrary host file deletion via ld.so cache cleanup paths.
- Fixes shipped for Ubuntu 20.04 LTS, 22.04 LTS, and 24.04 LTS.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-34078 +1 in the same advisory: …34079 | Flatpak is a Linux application sandboxing and distribution framework. Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4. NVD description · AI analysis pending | 9.3 group max | 2% |
| — |
It was discovered that Flatpak did not properly validate paths in sandbox-expose options. A malicious or compromised Flatpak app could use app-controlled symlinks to access arbitrary host files and gain code execution in the host context. This issue was addressed in Ubuntu Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-34078) It was discovered that Flatpak did not properly validate paths when removing outdated ld.so cache files. A malicious or compromised Flatpak app could use this issue to delete arbitrary files on the host. (CVE-2026-34079)
This source does not provide full text. Read it at ubuntu.com.