[CLSA-2026:1780908222] flatpak: Fix of CVE-2026-34078
Type:
security
Severity:
Critical
Release date:
2026-06-08 08:44:09 UTC
Description:
- CVE-2026-34078: backport the AlmaLinux/RHSA-2026:21755 fix series (29 commits + libglnx-chase update) to defeat sandbox-expose symlink races; preserves 1.12.7 baseline.
CVEs fixed:
Updated packages:
  • flatpak-1.12.7-2.el9_2.tuxcare.els6.i686.rpm
    sha:a59992331b777c6b0791a6cd2b0c71293fa192ebd442ab4698e5589976c37570
  • flatpak-1.12.7-2.el9_2.tuxcare.els6.x86_64.rpm
    sha:8643251fe26efb4c326b1e676b3e1a0689b1a6e752e9f98c95c6cebbfa4ea75d
  • flatpak-devel-1.12.7-2.el9_2.tuxcare.els6.i686.rpm
    sha:e8ea19877a09f554eb63e4b413c52e0cb147b6bd079cc2c6f9e1767b6b8effef
  • flatpak-devel-1.12.7-2.el9_2.tuxcare.els6.x86_64.rpm
    sha:ad3d2dd819b2f969c188580b4b20f917d0c64e8ea9fdb2584aa92c3b9fcdca5f
  • flatpak-libs-1.12.7-2.el9_2.tuxcare.els6.i686.rpm
    sha:161cb830dddf3ab795041a32b4ba00cd6ad80325a38bcf01fff93a02d545511a
  • flatpak-libs-1.12.7-2.el9_2.tuxcare.els6.x86_64.rpm
    sha:a07551df6f242b70a04f82629b488cc50cca6a125dc13842ae857a14af28481a
  • flatpak-selinux-1.12.7-2.el9_2.tuxcare.els6.noarch.rpm
    sha:078b1856517a9dff75078e52cfda076d86d04679b552839a4bd1f6f5e7b62287
  • flatpak-session-helper-1.12.7-2.el9_2.tuxcare.els6.i686.rpm
    sha:a70e1b686af9903ff8ca17de61ae75e4baf4f8f52fbca16f9f8343bf33131a39
  • flatpak-session-helper-1.12.7-2.el9_2.tuxcare.els6.x86_64.rpm
    sha:0ce6c80757f0dac43215a08575e3992497c2f615a9a9560155e46dd7bc743d00
  • flatpak-tests-1.12.7-2.el9_2.tuxcare.els6.x86_64.rpm
    sha:8bda50da6d4d2bd7ec3fd7438943275be8aa7c4acfb94ccf4f83c062c6a50240
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.