SUSE-SU-2026:1713-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20261713-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1713-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:1713-1
Upstream
CVE (2)
Related
Published
2026-05-06T12:06:52Z
Modified
2026-05-07T08:45:51Z
Summary
Security update for flatpak
Details

This update for flatpak fixes the following issues:

  • CVE-2026-34078: Arbitrary code execution via crafted symlinks in sandbox-expose options (bsc#1261769).
  • CVE-2026-34079: Arbitrary file deletion on host via improper cache file path validation (bsc#1261770).
References

Affected packages