Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Gentoo GLSA

GLSA 202608-06: Flatpak: Multiple Vulnerabilities

Multiple vulnerabilities in Flatpak, including a critical sandbox escape flaw (CVE-2026-34078, CVSS 10.0), affect all versions prior to 1.16.4. The vulnerabilities are locally exploitable, with the most severe allowing an attacker to break out of the application sandbox. All users must upgrade to Flatpak version 1.16.4 immediately, as no workaround is available.
Read Full Article →

Multiple vulnerabilities have been found in Flatpak, the worst of which allows sandbox escape. Affected packages Package sys-apps/flatpak on all architectures Affected versions < 1.16.4 Unaffected versions >= 1.16.4 Background Flatpak is a Linux application sandboxing and distribution framework. Description Multiple vulnerabilities have been discovered in Flatpak. Please review the CVE identifiers referenced below for details. Impact Please review the referenced CVE identifiers for details. Workaround There is no known workaround at this time. Resolution All Flatpak users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=sys-apps/flatpak-1.16.4" References CVE-2026-34078 CVE-2026-34079 Release date August 14, 2026 Latest revision August 14, 2026: 1 Severity high Exploitable local Bugzilla entries 972414

Share this article