Flatpak 1.16.4 fixed CVE-2026-34078, a critical flaw that could let a Flatpak app follow an app-controlled symlink and expose a host path inside its sandbox. The Flatpak project said the flaw could permit arbitrary host-file reads and writes and code execution in the host context. The fix in 1.16.4 addresses this vulnerability; it does not establish that 1.16.4 is a complete current security baseline.
What CVE-2026-34078 did
The vulnerability was in Flatpak’s portal handling of sandbox-expose paths. An app could supply a path containing a symlink it controlled. Flatpak run could follow that link, resolve it to a host path, and mount the resolved path into the sandbox, undermining the isolation boundary for the affected access.
The Flatpak project rated CVE-2026-34078 Critical and described the impact this way: “Every Flatpak app is able to read and write arbitrary files on the host and execute code in the host context.” This is the advisory’s stated potential impact, not a report of a measured number of affected users or confirmed incidents. Flatpak security advisory for CVE-2026-34078
Which Flatpak versions were affected
For this specific issue, the upstream advisory identifies versions earlier than 1.16.4 as affected and 1.16.4 as patched. That is a historical fix boundary for CVE-2026-34078, not proof that an installation running 1.16.4 is protected from every later vulnerability.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors#1 Best Overall
- Powerful Linux Laptop: This IdeaPad Slim 3 Laptop comes pre-installed with Ubuntu Linux, offering fast performance, robust security, and a clean, user-friendly experience. Enjoy full customization, seamless hardware compatibility, and access to thousands of open-source apps. Whether you're working, creating, or coding, it's built to keep up with everything you do.
- A Multitasking Master: The latest AMD Ryzen 7 5825U processor (up to 4.5 GHz) delivers powerful performance with 8 cores and 16 threads for smooth multitasking. Integrated AMD Radeon Graphics provide crisp visuals for streaming, browsing, photo editing, and casual gaming. With smart machine intelligence, it adapts to your needs for a fast, responsive experience.
- 15.6" Full HD Display: The IdeaPad Slim 3 boasts an 88% screen-to-body ratio for a floating, edge-to-edge visual experience. TÜV Low Blue Light certification reduces eye strain, making it perfect for long work or study sessions.
- Military-Grade Durability: The smart IdeaPad Slim 3 combines portability and durability, letting you work, study, and play on the go. With a profile 10% slimmer than the previous generation, it's lightweight yet military-grade rugged, ready for anything, anywhere.
- Versatile Connectivity: Enjoy the security of a built-in webcam with a privacy shutter. Connect effortlessly with multiple ports: 2x USB A, 1x USB C, 1x HDMI, 1x SD Card Reader, 1x Headphone/Microphone combo. Bundle comes with Stylus Pen, 256GB Portable SSD and 5-in-1 Docking Station.
Distribution packages can include security fixes backported without adopting the corresponding upstream version number. Check your Linux distribution’s security notice and installed package status rather than judging exposure from the upstream version string alone. Flatpak’s security policy identifies 1.18.x as the stable branch and recommends using current distribution packages.
What to do now
- Update Flatpak through your distribution’s supported package manager. Install the package that your distribution currently identifies as patched. The right package name, command, and version depend on your distribution and release; no single command or version is safe to prescribe for every Linux system.
- Check the distribution’s security advisory or package changelog. Confirm that it addresses CVE-2026-34078, including any backport, and look for later Flatpak fixes as well.
- Do not treat 1.16.4 as a universal current target. A later critical advisory, CVE-2026-90616, affects versions through 1.18.0 and names 1.18.1 as patched; it also notes fixes backported in the
flatpak-1.16.xbranch for LTS distributions. Use the package guidance for your own distribution. Flatpak security advisory for CVE-2026-90616
Why disabling the portal is only an interim option
The maintainer lists disabling the Flatpak Portal as a mitigation for CVE-2026-34078, but warns that applications can misbehave when it is disabled. It is therefore a potentially disruptive temporary measure, not a universal substitute for installing a patched package. Prefer your distribution’s current security update and follow its guidance if you cannot apply it immediately.
Rank #2
- Intel Core i5-10210U (up to 4.2GHz) - 1TB PCIe NVMe + 1TB HDD - 32GB DDR4 SDRAM
- 17.3" HD+ (1600x900) Display, Intel UHD Graphics 620
- Built in HD 720p Webcam with Microphone - Bluetooth Version4.2
- I/O Ports: 2x USB 3.1 (Data Only), 1x USB 2.0, 1x HDMI, 1x Headphone/Microphone Combo Jack
- Linux Mint Cinnamon 64-Bit - 6-Row Keyboard w/ Full Numberpad
Why package status matters more than the version string alone
Upstream releases and distribution packages do not always move in lockstep: vendors may backport a security fix to a package based on an older upstream branch. Conversely, a version that fixed one CVE may not include later fixes. Flatpak’s release notes provide upstream release context, while the distribution’s own advisory is the relevant source for whether its package has been patched.
Quick Recap
Best Value
- 12th Intel Alder Lake N95 Processor – The GMKtec G3 S Mini PC is powered by the 12th Gen Intel N95 processor with 4 cores, 4 threads, 6MB cache and a burst frequency up to 3.4GHz. Compared with N100/N5105/N5100/N5095, the N95 delivers up to 36% overall performance improvement. Perfect for routine tasks, office work, and home entertainment, this compact mini desktop is more convenient than traditional bulky PCs.
- 8GB RAM & 256GB SSD Storage – Pre-installed with 8GB DDR4 memory and a fast 256GB M.2 2242 SSD, the G3 S mini desktop offers quicker startup, smoother multitasking, and faster file transfers. Enjoy seamless performance whether you’re working on multiple applications, browsing, or streaming content.
- Rich Interfaces & Connectivity – The G3 S mini computer comes equipped with USB 3.2 (up to 10Gbps), dual HDMI 2.0 (4K@60Hz), and a 3.5mm audio jack. With support for WiFi 5, Bluetooth 5.0, and Gigabit Ethernet (RJ45 1000MbE), it connects easily with monitors, projectors, printers, office equipment, and other peripherals, making it versatile for both home and business use.
- Dual 4K Display Support – Featuring upgraded Intel UHD Graphics (up to 1000MHz), the G3 S supports 4K video playback and AV1 decoding for a smooth viewing experience. With dual HDMI outputs, you can connect two 4K@60Hz displays simultaneously, enabling efficient multitasking for work and entertainment.
- GMKtec WARRANTY - GMKtec offers a 1-year limited GMKtec's warranty for each mini PC, starting from the date of the purchase. All defects due to design and workmanship are covered. With a professional after sales team always ready to attend to your needs, you can simply relax and enjoy your mini PC.
Rank #4
Rank #3
- Intel Core i5-1335U Processor (12M Cache, 12 Threads, up to 4.6 GHz) - 256GB Solid State Drive - 16GB DDR4 SDRAM
- 15.6" FHD (1920x1080) Non-Touch Anti-Glare Display - Intel UHD 620 Integrated Graphics - Stereo Speakers
- 720p HD Webcam with Privacy Shutter. Integrated Microphone - Intel Dual Band Wireless-AC (2x2) 8265, Bluetooth Version 4.2
- I/O Ports: 2x USB 3.0, 1x USB 3.1 Type-C 3.1, Headphone/Mic Combo Port, 4-in-1 Card Reader, HDMI, Kensington Mini-Lock Slot
- Linux Mint (Cinnamon) 64-Bit - Keyboard with Full NumberPad - Fast Charging
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

