REDHAT-BUG-2456276: High severity Flatpak Flatpak vulnerability
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
flatpakto a version that resolves this vulnerability.Fixed in 1.16.4
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2456276?
The severity of REDHAT-BUG-2456276 is classified as high, with a score of 7.
How do I fix REDHAT-BUG-2456276?
To fix REDHAT-BUG-2456276, update Flatpak to version 1.16.4 or later.
What are the risks associated with REDHAT-BUG-2456276?
The risks associated with REDHAT-BUG-2456276 include unauthorized access to arbitrary paths in the host system by sandboxed applications.
When was REDHAT-BUG-2456276 published?
REDHAT-BUG-2456276 was published on April 7, 2026.
What is the impact of REDHAT-BUG-2456276 on Flatpak users?
The impact of REDHAT-BUG-2456276 on Flatpak users includes potential exposure to security vulnerabilities due to improper handling of symlinks.