Bug 35336 - flatpak 4 new security issues, including CVE-2026-3407[89]
Summary: flatpak 4 new security issues, including CVE-2026-3407[89]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2026-04-09 09:33 CEST by Nicolas Salguero
Modified: 2026-05-15 12:21 CEST (History)
3 users (show)

See Also:
Source RPM: flatpak-1.14.10-1.mga9.src.rpm
CVE: CVE-2026-34078, CVE-2026-34079
Status comment:
andrewsfarm: test_passed_mga9_64+


Attachments

Nicolas Salguero 2026-04-09 09:34:08 CEST

CVE: (none) => CVE-2026-34078, CVE-2026-34079
Flags: (none) => affects_mga9+
Source RPM: (none) => flatpak-1.16.3-1.mga10.src.rpm, flatpak-1.14.10-1.mga9.src.rpm
Status comment: (none) => Fixed upstream in 1.16.5
Whiteboard: (none) => MGA9TOO

Comment 1 Nicolas Salguero 2026-04-09 09:52:59 CEST
For Cauldron, I asked for a freeze move.

Whiteboard: MGA9TOO => (none)
Flags: affects_mga9+ => (none)
Source RPM: flatpak-1.16.3-1.mga10.src.rpm, flatpak-1.14.10-1.mga9.src.rpm => flatpak-1.14.10-1.mga9.src.rpm
Version: Cauldron => 9

Comment 2 Nicolas Salguero 2026-04-10 15:13:06 CEST
Version 1.16.5 caused some regressions, for instance, chromium does not work.

See:
https://github.com/flatpak/flatpak/issues/6582
https://github.com/flatpak/flatpak/issues/6583
https://github.com/flatpak/flatpak/issues/6584
Comment 3 Nicolas Salguero 2026-04-11 10:39:28 CEST
For Cauldron, I asked for a freeze move of version 1.16.6, which fixes those regressions.

Status comment: Fixed upstream in 1.16.5 => Fixed upstream in 1.16.6

Comment 4 Lewis Smith 2026-04-14 21:42:39 CEST
Thanks again to Nicolas, Cauldron done; leaves M9.

Assignee: bugsquad => pkg-bugs

Comment 5 Morgan Leijström 2026-04-20 12:48:31 CEST
This is listed as critical security.

Can the mga9 1.14 version be updated or do this need an upgrade to 1.16?

CC: (none) => fri

Comment 6 Nicolas Salguero 2026-04-27 11:26:31 CEST
Debian has issued an advisory on April 22:
https://lists.debian.org/debian-security-announce/2026/msg00133.html

Status comment: Fixed upstream in 1.16.6 => Fixed upstream in 1.16.6 and patches available from Debian

Comment 7 Nicolas Salguero 2026-05-13 14:46:26 CEST
Suggested advisory:
========================

The updated packages fix security vulnerabilities:

Complete sandbox escape leading to host file access and code execution in the host context. (CVE-2026-34078)

Arbitrary file deletion on the host filesystem. (CVE-2026-34079)

References:
https://www.openwall.com/lists/oss-security/2026/04/09/3
https://github.com/flatpak/flatpak/security/advisories/GHSA-cc2q-qc34-jprg
https://github.com/flatpak/flatpak/security/advisories/GHSA-p29x-r292-46pp
https://github.com/flatpak/flatpak/security/advisories/GHSA-2fxp-43j9-pwvc
https://github.com/flatpak/flatpak/security/advisories/GHSA-89xm-3m96-w3jg
https://lists.debian.org/debian-security-announce/2026/msg00133.html
========================

Updated packages in core/updates_testing:
========================
flatpak-1.14.10-1.1.mga9
flatpak-tests-1.14.10-1.1.mga9
lib64flatpak-devel-1.14.10-1.1.mga9
lib64flatpak-gir1.0-1.14.10-1.1.mga9
lib64flatpak0-1.14.10-1.1.mga9

from SRPM:
flatpak-1.14.10-1.1.mga9.src.rpm

Status: NEW => ASSIGNED
Assignee: pkg-bugs => qa-bugs
Status comment: Fixed upstream in 1.16.6 and patches available from Debian => (none)

Comment 8 Thomas Andrews 2026-05-13 17:17:33 CEST
No installation issues. Tested with Discover to update my SurfShark VPN app with no issues. Also installed Space Cadet Pinball from Flathub with no issues, played a game.

Looks OK. Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update
Whiteboard: (none) => MGA9-64-OK
Flags: (none) => test_passed_mga9_64+

katnatek 2026-05-14 01:34:39 CEST

Keywords: (none) => advisory

Comment 9 Mageia Robot 2026-05-14 04:44:33 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2026-0133.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED

Comment 10 Morgan Leijström 2026-05-15 12:21:20 CEST
Yep OK for me too
64 bit, our released backport kernel 6.18.4-desktop-3.stabletesting
flatpak update
flatpak remove --unused
Used Cromium and Signal
Launch tests of Zoom, KiCad, FreeFileSync

Note You need to log in before you can comment on or make changes to this bug.