OESA-2026-3852

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3852
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3852.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3852
Upstream
Published
2026-09-14T16:35:01Z
Modified
2026-09-13T16:45:49Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
flatpak security update
Details

flatpak is a system for building, distributing and running sandboxed desktop applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for more information.

Security Fix(es):

A vulnerability, which was classified as very critical, has been found in Flatpak up to 1.10.7/1.12.7/1.14.3/1.15.3.Using CWE to declare the problem leads to CWE-20. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.Impacted is confidentiality, integrity, and availability.Upgrading to version 1.10.8, 1.12.8, 1.14.4 or 1.15.4 eliminates this vulnerability.(CVE-2023-28100)

Database specific
{
    "severity": "Critical"
}
References

Affected packages

openEuler:20.03-LTS-SP4 / flatpak

Package

Name
flatpak
Purl
pkg:rpm/openEuler/flatpak&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.3-15.oe2003sp4

Ecosystem specific

{
    "aarch64": [
        "flatpak-1.0.3-15.oe2003sp4.aarch64.rpm",
        "flatpak-debuginfo-1.0.3-15.oe2003sp4.aarch64.rpm",
        "flatpak-debugsource-1.0.3-15.oe2003sp4.aarch64.rpm",
        "flatpak-devel-1.0.3-15.oe2003sp4.aarch64.rpm"
    ],
    "noarch": [
        "flatpak-help-1.0.3-15.oe2003sp4.noarch.rpm"
    ],
    "src": [
        "flatpak-1.0.3-15.oe2003sp4.src.rpm"
    ],
    "x86_64": [
        "flatpak-1.0.3-15.oe2003sp4.x86_64.rpm",
        "flatpak-debuginfo-1.0.3-15.oe2003sp4.x86_64.rpm",
        "flatpak-debugsource-1.0.3-15.oe2003sp4.x86_64.rpm",
        "flatpak-devel-1.0.3-15.oe2003sp4.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3852.json"