CVE-2026-2604

NameCVE-2026-2604
DescriptionA flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4503-1
Debian Bugs1128332

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
evolution-data-server (PTS)bullseye3.38.3-1+deb11u2vulnerable
bullseye (security)3.38.3-1+deb11u3fixed
bookworm3.46.4-2vulnerable
trixie3.56.2-0+deb13u1vulnerable
forky, sid3.56.2-8fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
evolution-data-serversourcebullseye3.38.3-1+deb11u3DLA-4503-1
evolution-data-serversource(unstable)3.56.2-81128332

Notes

https://gitlab.gnome.org/GNOME/evolution-data-server/-/issues/627
Fixed by: https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/afa12b6ba502e5acaa431415aa3b939ddb377382

Search for package or bug name: Reporting problems