ELA-1660-1 evolution-data-server security update

avoid deletion of arbitrary files on the host

2026-03-22
Packageevolution-data-server
Version3.22.7-1+deb9u3 (stretch), 3.30.5-1+deb10u3 (buster)
Related CVEs CVE-2026-2604


An issue has been found in evolution-data-server, an evolution database backend server. A Flatpak application with D-Bus access to the addressbook service can delete arbitrary files on the host, potentially including Flatpak override files. This fix canonicalizes the file path before performing a prefix comparison, ensuring that ../ sequences are resolved.



For Debian 10 buster, these problems have been fixed in version 3.30.5-1+deb10u3.

For Debian 9 stretch, these problems have been fixed in version 3.22.7-1+deb9u3.

We recommend that you upgrade your evolution-data-server packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.