[CLSA-2026:1779700633] flatpak: Fix of CVE-2026-34079
Type:
security
Severity:
Important
Release date:
2026-05-25 09:17:17 UTC
Description:
- CVE-2026-34079: fix arbitrary host file deletion via app-controlled ld.so cache symlink in flatpak_switch_symlink_and_remove
Updated packages:
  • flatpak-1.0.9-10.amzn2.0.7.tuxcare.els1.x86_64.rpm
    sha:68491b4500c766e94f6fdb63beb48e90d99d0ac07f4b1d81247a70fffae594d8
  • flatpak-builder-1.0.0-10.amzn2.0.7.tuxcare.els1.x86_64.rpm
    sha:94833b77920bb98131216eb5eea368f784b8c37ed25e0974c072e2c055751a1a
  • flatpak-devel-1.0.9-10.amzn2.0.7.tuxcare.els1.x86_64.rpm
    sha:197f188370b413e3b5fbcd06ba145e384bc0911fcba595e07a193d90649531d7
  • flatpak-libs-1.0.9-10.amzn2.0.7.tuxcare.els1.x86_64.rpm
    sha:635cdee39ef45f8b6098eee4f365d58442e40918bc037239c505df8d19473605
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.