Alerts This Week
Warning Icon 1 469
Alerts This Week
Warning Icon 1 469

Mageia 9 Flatpak Critical Sandbox Escape Vulnerability File Deletion Risk

mageia
Calendar Grey May 14, 2026
Dist Mageia Esm H88
Updated flatpak packages for Mageia address critical sandbox escape and arbitrary file access issues.
MGASA-2026-0133 - Updated flatpak packages fix security vulnerabilities

Summary

Description: Complete sandbox escape leading to host file access and code execution in the host context. (CVE-2026-34078) Arbitrary file deletion on the host filesystem. (CVE-2026-34079)

References

- https://bugs.mageia.org/show_bug.cgi?id=35336

- https://www.openwall.com/lists/oss-security/2026/04/09/3

- https://github.com/flatpak/flatpak/security/advisories/GHSA-cc2q-qc34-jprg

- https://github.com/flatpak/flatpak/security/advisories/GHSA-p29x-r292-46pp

- https://github.com/flatpak/flatpak/security/advisories/GHSA-2fxp-43j9-pwvc

- https://github.com/flatpak/flatpak/security/advisories/GHSA-89xm-3m96-w3jg

- https://lists.debian.org/debian-security-announce/2026/msg00133.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34078

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34079

Resolution

SRPMS

- 9/core/flatpak-1.14.10-1.1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 14 May 2026
URL: https://advisories.mageia.org/MGASA-2026-0133.html
Type: security
CVE: CVE-2026-34078, CVE-2026-34079

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here