REDHAT-BUG-2456284: Medium severity Flatpak Flatpak vulnerability
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. This vulnerability is fixed in 1.16.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
flatpakto a version that resolves this vulnerability.Fixed in 1.16.4
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2456284?
The severity of REDHAT-BUG-2456284 is classified as medium (4).
How do I fix REDHAT-BUG-2456284?
To fix REDHAT-BUG-2456284, update Flatpak to version 1.16.4 or later.
What impact does REDHAT-BUG-2456284 have on my system?
REDHAT-BUG-2456284 allows Flatpak apps to potentially delete arbitrary files due to improper cache file handling.
Which applications are affected by REDHAT-BUG-2456284?
Flatpak applications that are using versions prior to 1.16.4 are affected by REDHAT-BUG-2456284.
When was REDHAT-BUG-2456284 published?
REDHAT-BUG-2456284 was published on April 7, 2026.