RHSA-2026:35843: Important: flatpak security update
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.Security Fix(es): flatpak: Flatpak: Arbitrary code execution via crafted symlinks in sandbox-expose options (CVE-2026-34078) flatpak: Flatpak: Arbitrary file deletion on host via improper cache file path validation (CVE-2026-34079) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/flatpakto a version that resolves this vulnerability.Fixed in 1.12.9-3.el7_9 - Upgrade
Upgrade
redhat/flatpak-builderto a version that resolves this vulnerability.Fixed in 1.0.0-16.el7_9 - Upgrade
Upgrade
redhat/flatpak-debuginfoto a version that resolves this vulnerability.Fixed in 1.12.9-3.el7_9 - Upgrade
Upgrade
redhat/flatpak-develto a version that resolves this vulnerability.Fixed in 1.12.9-3.el7_9 - Upgrade
Upgrade
redhat/flatpak-libsto a version that resolves this vulnerability.Fixed in 1.12.9-3.el7_9
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:35843?
The severity of RHSA-2026:35843 is classified as high with a score of 7.
What is RHSA-2026:35843?
RHSA-2026:35843 is a security update for flatpak that addresses vulnerabilities in Red Hat Enterprise Linux.
How do I fix RHSA-2026:35843?
To fix RHSA-2026:35843, you should apply the latest flatpak security updates provided by Red Hat.
What software is impacted by RHSA-2026:35843?
RHSA-2026:35843 impacts Red Hat Enterprise Linux Server across various architectures including IBM Power and z Systems.
When was RHSA-2026:35843 published?
RHSA-2026:35843 was published on July 6, 2026.