Bionic is partially fixed (only CVE-2026-34079 was addressed), as the changes
for CVE-2026-34078 are too intrusive.
Resolute is not affected.
** Changed in: flatpak (Ubuntu)
Assignee: (unassigned) => Chrisa Oikonomou (yomonokio)
** Changed in: flatpak (Ubuntu Noble)
Status: In Progress => Fix Released
** Changed in: flatpak (Ubuntu Focal)
Status: New => Fix Released
** Changed in: flatpak (Ubuntu Jammy)
Status: New => Fix Released
** Changed in: flatpak (Ubuntu Bionic)
Status: New => Fix Released
** Changed in: flatpak (Ubuntu Resolute)
Status: Fix Released => Deferred
--
You received this bug notification because you are a member of Ubuntu
Desktop Bugs, which is subscribed to flatpak in Ubuntu.
https://bugs.launchpad.net/bugs/2150371
Title:
CVE-2026-34078: Complete sandbox escape, CVE-2026-34079: Arbitrary
file deletion
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/flatpak/+bug/2150371/+subscriptions
--
desktop-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/desktop-bugs