Home / mailingsPDF  

[USN-8741-1] Flatpak vulnerabilities

Posted on 10 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8741-1
September 10, 2026

flatpak vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Flatpak could be made to access files outside its sandbox or delete
arbitrary files on the host.

Software Description:
- flatpak: Application deployment framework for desktop apps

Details:

It was discovered that Flatpak did not properly validate paths in
sandbox-expose options. A malicious or compromised Flatpak app could
use app-controlled symlinks to access arbitrary host files and gain
code execution in the host context. This issue was addressed in Ubuntu
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-34078)

It was discovered that Flatpak did not properly validate paths when
removing outdated ld.so cache files. A malicious or compromised Flatpak
app could use this issue to delete arbitrary files on the host.
(CVE-2026-34079)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
flatpak 1.14.6-1ubuntu0.1+esm1
Available with Ubuntu Pro
libflatpak0 1.14.6-1ubuntu0.1+esm1
Available with Ubuntu Pro

Ubuntu 22.04 LTS
flatpak 1.12.7-1ubuntu0.1+esm1
Available with Ubuntu Pro
libflatpak0 1.12.7-1ubuntu0.1+esm1
Available with Ubuntu Pro

Ubuntu 20.04 LTS
flatpak 1.6.5-0ubuntu0.5+esm1
Available with Ubuntu Pro
libflatpak0 1.6.5-0ubuntu0.5+esm1
Available with Ubuntu Pro

Ubuntu 18.04 LTS
flatpak 1.0.9-0ubuntu0.4+esm1
Available with Ubuntu Pro
libflatpak0 1.0.9-0ubuntu0.4+esm1
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8741-1
CVE-2026-34078, CVE-2026-34079

--===============6553723235621217566==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP