CVE-2026-34079 is a high-severity vulnerability in Flatpak, a Linux application sandboxing and distribution framework. Prior to version 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. The vulnerability is fixed in version 1.16.4. [truncated]
CVE-2026-34078 is a critical vulnerability in the Flatpak Linux application sandboxing and distribution framework. Prior to version 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. The vulnerability is fi [truncated]
CVE-2026-34080 is a medium-severity vulnerability in xdg-dbus-proxy, a filtering proxy for D-Bus connections. The vulnerability allows clients to intercept D-Bus messages they should not have access to due to a policy parser issue. The issue arises from the proxy's failure to properly handle eavesdrop restrictions, specifically when there is a space before the equals sign in policy rules. This vulnerabili [truncated]