Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Fedora 42 Flatpak 1.16.6 Critical Security Fixes for Code Execution

fedora
Calendar Grey April 28, 2026
Dist Fedora Esm H88
Flatpak 1.16.6 addresses critical security issues including arbitrary code execution and file deletion risks.
Update to 1.16.6 Fixes for CVE-2026-34078, CVE-2026-34079, GHSA-2fxp-43j9-pwvc and GHSA-89xm-3m96-w3jg

Summary

flatpak is a system for building, distributing and running sandboxed desktop

applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for

more information.

Update Information:

Update to 1.16.6 Fixes for CVE-2026-34078, CVE-2026-34079, GHSA-2fxp-43j9-pwvc and GHSA-89xm-3m96-w3jg

Change Log

* Fri Apr 10 2026 Michael Catanzaro - 1.16.6-1 - Update to 1.16.6 * Wed Apr 8 2026 David King - 1.16.4-1 - Update to 1.16.4

References


[ 1 ] Bug #2456383 - CVE-2026-34078 flatpak: Flatpak: Arbitrary code execution via crafted symlinks in sandbox-expose options [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2456383 [ 2 ] Bug #2456394 - CVE-2026-34079 flatpak: Flatpak: Arbitrary file deletion on host via improper cache file path validation [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2456394

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2a3e305ac4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: flatpak
Product: Fedora 42
Version: 1.16.6
Release: 1.fc42
Summary: Application deployment framework for desktop apps

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here