{"id":"SUSE-SU-2026:4610-1","summary":"Security update for flatpak","details":"This update for flatpak fixes the following issues:\n\n- CVE-2026-90616: missing symlink protection allows a malicious sandboxed app to obtain arbitrary read and write access\n  to files on the host (bsc#1280236).\n- CVE-2026-92162: path traversal via unvalidated `arch` parameter in `DeployAppstream` (bsc#1282514).\n- CVE-2026-96275: arbitrary write access as root via extra-data extraction (bsc#1282515).\n- CVE-2026-96276: arbitrary write in host context via `flatpak build-init` (bsc#1282516).\n- CVE-2026-96281: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes (bsc#1282519).\n- CVE-2026-96282: extension metadata path traversal file existence oracle (bsc#1282520).\n- CVE-2026-96283: flatpak-system-helper: cross-user `CancelPull` orphans another user's ongoing pull (bsc#1282521).\n- CVE-2026-96807: fixed-filename writes to arbitrary locations via symlink attack on `.ld.so` (bsc#1282523).\n- CVE-2026-96808: `revokefs` symlink path traversal allows local privilege escalation via commit tampering\n  (bsc#1282524).\n","modified":"2026-10-10T09:30:06.446561391Z","published":"2026-10-09T15:55:00Z","related":["CVE-2026-90616","CVE-2026-92162","CVE-2026-96275","CVE-2026-96276","CVE-2026-96281","CVE-2026-96282","CVE-2026-96283","CVE-2026-96807","CVE-2026-96808"],"upstream":["CVE-2026-90616","CVE-2026-92162","CVE-2026-96275","CVE-2026-96276","CVE-2026-96281","CVE-2026-96282","CVE-2026-96283","CVE-2026-96807","CVE-2026-96808"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264610-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280236"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282514"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282515"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282516"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282519"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282520"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282521"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282523"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282524"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-90616"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92162"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-96275"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-96276"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-96281"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-96282"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-96283"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-96807"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-96808"}],"affected":[{"package":{"name":"flatpak","ecosystem":"SUSE:Linux Enterprise Server 12 SP5-LTSS","purl":"pkg:rpm/suse/flatpak&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.2-3.15.1"}]}],"ecosystem_specific":{"binaries":[{"typelib-1_0-Flatpak-1_0":"1.4.2-3.15.1","flatpak":"1.4.2-3.15.1","libflatpak0":"1.4.2-3.15.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4610-1.json"}},{"package":{"name":"flatpak","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/flatpak&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.2-3.15.1"}]}],"ecosystem_specific":{"binaries":[{"libflatpak0":"1.4.2-3.15.1","typelib-1_0-Flatpak-1_0":"1.4.2-3.15.1","flatpak":"1.4.2-3.15.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4610-1.json"}}],"schema_version":"1.9.0"}