CLSA-2026-1776949031

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776949031.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2026-1776949031
Upstream
  • CVE-2026-34079
Published
2026-04-23T12:57:16Z
Modified
2026-06-01T00:32:27.504069566Z
Summary
flatpak: Fix of CVE-2026-34079
Details
  • CVE-2026-34079: restrict cached-file removal to alphanumeric targets in flatpakswitchsymlinkandremove to prevent path-traversal unlink via a sandboxed-app-controlled symlink
References

Affected packages

TuxCare:AlmaLinux:9.2
flatpak

Package

Name
flatpak
Purl
pkg:rpm/tuxcare/flatpak?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.7-2.el9.tuxcare.els5

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776949031.json"
flatpak-devel

Package

Name
flatpak-devel
Purl
pkg:rpm/tuxcare/flatpak-devel?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.7-2.el9.tuxcare.els5

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776949031.json"
flatpak-libs

Package

Name
flatpak-libs
Purl
pkg:rpm/tuxcare/flatpak-libs?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.7-2.el9.tuxcare.els5

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776949031.json"
flatpak-selinux

Package

Name
flatpak-selinux
Purl
pkg:rpm/tuxcare/flatpak-selinux?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.7-2.el9.tuxcare.els5

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776949031.json"
flatpak-session-helper

Package

Name
flatpak-session-helper
Purl
pkg:rpm/tuxcare/flatpak-session-helper?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.7-2.el9.tuxcare.els5

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776949031.json"
flatpak-tests

Package

Name
flatpak-tests
Purl
pkg:rpm/tuxcare/flatpak-tests?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.7-2.el9.tuxcare.els5

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1776949031.json"