RHSA-2026:30901: Important: flatpak security update
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.Security Fix(es): flatpak: Flatpak: Arbitrary code execution via crafted symlinks in sandbox-expose options (CVE-2026-34078) flatpak: Flatpak: Arbitrary file deletion on host via improper cache file path validation (CVE-2026-34079) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/flatpakto a version that resolves this vulnerability.Fixed in 1.12.9-2.el8_4 - Upgrade
Upgrade
redhat/flatpak-debuginfoto a version that resolves this vulnerability.Fixed in 1.12.9-2.el8_4 - Upgrade
Upgrade
redhat/flatpak-debugsourceto a version that resolves this vulnerability.Fixed in 1.12.9-2.el8_4 - Upgrade
Upgrade
redhat/flatpak-libsto a version that resolves this vulnerability.Fixed in 1.12.9-2.el8_4 - Upgrade
Upgrade
redhat/flatpak-libs-debuginfoto a version that resolves this vulnerability.Fixed in 1.12.9-2.el8_4 - Upgrade
Upgrade
redhat/flatpak-selinuxto a version that resolves this vulnerability.Fixed in 1.12.9-2.el8_4 - Upgrade
Upgrade
redhat/flatpak-session-helperto a version that resolves this vulnerability.Fixed in 1.12.9-2.el8_4 - Upgrade
Upgrade
redhat/flatpak-session-helper-debuginfoto a version that resolves this vulnerability.Fixed in 1.12.9-2.el8_4 - Upgrade
Upgrade
redhat/flatpak-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.12.9-2.el8_4 - Upgrade
Upgrade
flatpakto a version that resolves this vulnerability.Patch CVE-2026-34078 - Upgrade
Upgrade
flatpakto a version that resolves this vulnerability.Patch CVE-2026-34079
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:30901?
The severity of RHSA-2026:30901 is classified as high with a score of 7.
What vulnerabilities does RHSA-2026:30901 address?
RHSA-2026:30901 addresses vulnerabilities related to arbitrary code execution and arbitrary file deletion due to improper cache file handling.
How do I fix RHSA-2026:30901?
To fix RHSA-2026:30901, you should update your flatpak packages to the latest version provided by the security update.
What is the impact of not addressing RHSA-2026:30901?
Not addressing RHSA-2026:30901 can lead to potential arbitrary code execution and unauthorized file deletion on the host system.
When was RHSA-2026:30901 published?
RHSA-2026:30901 was published on June 29, 2026.