[CLSA-2026:1790037090] flatpak: Fix of CVE-2026-90616
Type:
security
Severity:
Important
Release date:
2026-09-22 00:31:40 UTC
Description:
- CVE-2026-34079: fix arbitrary host file deletion via app-controlled ld.so cache symlink in flatpak_switch_symlink_and_remove - CVE-2026-90616: rebase onto the 1.0.9-10.amzn2.0.8 vendor base, which creates the per-app directories in flatpak_ensure_data_dir() and binds them into the sandbox in flatpak_run_setup_base_argv() through the fd-relative libglnx chase API
CVEs fixed:
Updated packages:
  • flatpak-1.0.9-10.amzn2.0.8.tuxcare.els1.x86_64.rpm
    sha:fcf3993c9b02316af49dca3ac176c4a988219db4b0373f67a6cb1520e53ba1bd
  • flatpak-builder-1.0.0-10.amzn2.0.8.tuxcare.els1.x86_64.rpm
    sha:f0b5ffb0e51a8025ac3b87dcf7681d3fffcb6d89b136f0e72b7054a2a5e3cff1
  • flatpak-devel-1.0.9-10.amzn2.0.8.tuxcare.els1.x86_64.rpm
    sha:675796e3c9ecf745fab5ce91422b2a9bdfb84b34f5381664939bdd0430574c95
  • flatpak-libs-1.0.9-10.amzn2.0.8.tuxcare.els1.x86_64.rpm
    sha:4b2f46bd913667561c5c7e9a3dc89bd3ecdb35ff54bbb512b910b2d75c0c3d57
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.