CVE-2026-34079: Flatpak affected by arbitrary file deletion on the host filesystem
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. This vulnerability is fixed in 1.16.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
flatpakto a version that resolves this vulnerability.Fixed in 1.16.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34079?
CVE-2026-34079 has been classified as a high severity vulnerability due to its potential for arbitrary file deletion on the host filesystem.
How do I fix CVE-2026-34079?
To mitigate CVE-2026-34079, upgrade Flatpak to version 1.16.4 or later, which addresses the vulnerability.
What applications are affected by CVE-2026-34079?
CVE-2026-34079 affects all versions of Flatpak prior to 1.16.4.
What type of vulnerability is CVE-2026-34079?
CVE-2026-34079 is an arbitrary file deletion vulnerability within the Flatpak framework.
Can CVE-2026-34079 impact system security?
Yes, CVE-2026-34079 can compromise system security by allowing unauthorized deletion of files on the host filesystem.