[From nobody Fri Aug 21 14:49:07 2026
Received: (at 1144130-close) by bugs.debian.org; 21 Aug 2026 13:47:33 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-113.0 required=4.0 tests=BAYES_00,DKIM_SIGNED,
 DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,FVGT_m_MULTI_ODD,
 HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,RCVD_IN_DNSWL_MED,
 SPF_HELO_PASS,SPF_PASS,USER_IN_DKIM_WELCOMELIST autolearn=ham
 autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 81; hammy, 150; neutral, 362; spammy,
 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz,
 0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo
Return-path: &lt;envelope@ftp-master.debian.org&gt;
Received: from mitropoulos.debian.org
 ([2001:648:2ffc:deb:216:61ff:fe9d:958d]:46198)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wxPam-008z5e-2h for 1144130-close@bugs.debian.org;
 Fri, 21 Aug 2026 13:47:33 +0000
Received: via submission
 from C=NA, ST=NA, L=Ankh Morpork, O=Debian SMTP, OU=Debian SMTP CA,
 CN=fasolo.debian.org, EMAIL=hostmaster@fasolo.debian.org (verified)
 by mitropoulos.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wxPak-00Euaq-1l for 1144130-close@bugs.debian.org;
 Fri, 21 Aug 2026 13:47:30 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
 Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
 :Content-Description:In-Reply-To:References;
 bh=x9uQ/HZSBvEKKs0bal7cOiG0pmwK5L6Nodxgm7qqOic=; b=QASbzd1PHSx+l1EWlQ61vimDrE
 fa8Zb55+Ho4hOggnOJgDgDpDNI4uFxO2PgrKBCLLGIEID6fkc6TCORqKJJBmjBZra9CCE7csTm8Iq
 K24lTth+j6jODXCRTjiV0vtVd6y8dQNoUa49nVjMZ5aNDEJolc1IcrIw5WQXyeTQ2iSlQyZN4CftJ
 MzxzXkTvr85xCV4QYZapWT4vKH7YxQ2qP5IxXMcLWRzNHDO1461YUg69uRtikJ2u6NGMjI+DntZWQ
 rZ/rLJIalcAdz+hG2rL9PSrKQOtqk0oYP0rx14c00fp7GQyae8avrDKGhDexjXPLQjVcPf9F+/vBu
 /6ZDnzLQ==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
 (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wxPaj-0000000EoXr-1bUh; Fri, 21 Aug 2026 13:47:29 +0000
From: Debian FTP Masters &lt;ftpmaster@ftp-master.debian.org&gt;
Reply-To: Simon McVittie &lt;smcv@debian.org&gt;
To: 1144130-close@bugs.debian.org
X-DAK: dak process-policy
X-Debian: DAK
X-Debian-Package: flatpak
Debian: DAK
Debian-Changes: flatpak_1.16.6-1~deb13u2_source.changes
Debian-Source: flatpak
Debian-Version: 1.16.6-1~deb13u2
Debian-Architecture: source
Debian-Suite: proposed-updates
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1144130: fixed in flatpak 1.16.6-1~deb13u2
Content-Type: multipart/signed; micalg=&quot;pgp-sha256&quot;;
 protocol=&quot;application/pgp-signature&quot;;
 boundary=&quot;===============5104066808550732804==&quot;
Message-Id: &lt;E1wxPaj-0000000EoXr-1bUh@fasolo.debian.org&gt;
Date: Fri, 21 Aug 2026 13:47:29 +0000

--===============5104066808550732804==
Content-Type: text/plain; charset=&quot;utf-8&quot;
Content-Transfer-Encoding: quoted-printable

Source: flatpak
Source-Version: 1.16.6-1~deb13u2
Done: Simon McVittie &lt;smcv@debian.org&gt;

We believe that the bug you reported is fixed in the latest version of
flatpak, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144130@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie &lt;smcv@debian.org&gt; (supplier of updated flatpak package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 11 Aug 2026 14:03:38 +0100
Source: flatpak
Architecture: source
Version: 1.16.6-1~deb13u2
Distribution: trixie-security
Urgency: high
Maintainer: Utopia Maintenance Team &lt;pkg-utopia-maintainers@lists.alioth.debi=
an.org&gt;
Changed-By: Simon McVittie &lt;smcv@debian.org&gt;
Closes: 1144130
Changes:
 flatpak (1.16.6-1~deb13u2) trixie-security; urgency=3Dhigh
 .
   * d/patches: Backport security fixes from 1.18.1 (Closes: #1144130)
     - d/p/libglnx/*.patch:
       Backport glnx_chase_and_mkdirat() utility function, required by some
       of the security fixes below
     - d/p/tests/*.patch:
       Backport unit tests fixes which are required by the tests for some
       of the security fixes below
     - d/p/GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/*.patch:
       + GHSA-fqx6-vh4p-42cg:
         Fix writing outside installation directory via crafted commit metada=
ta.
         A malicious or compromised Flatpak repository could write
         attacker-controlled files outside /var/lib/flatpak as root.
       + GHSA-8qxj-x646-phcm:
         Fix writing outside working directory in `flatpak build-init`.
         A malicious or compromised SDK could write outside the intended
         working directory when a developer starts using it for a build.
     - d/p/GHSA-qrwq-7qwx-q9rp/*.patch:
       Fix local privilege escalation involving revokefs.
       A malicious local user could write files outside /var/lib/flatpak
       as root by tampering with OSTree objects after signature verification.
     - d/p/GHSA-8688-9x26-hhxj/*.patch:
       Fix a sandbox escape involving directories inside ~/.var/app/APP_ID.
       A malicious or compromised Flatpak app could write to arbitrary files
       outside its sandbox.
     - d/p/GHSA-99wv-m8rp-g58x/*.patch:
       Fix a sandbox escape involving the ld.so cache.
       A malicious or compromised Flatpak app could write files with a fixed
       name and limited control over content outside the sandbox.
     - d/p/GHSA-v2gw-v9h5-9q4x/*.patch:
       Fix local privilege escalation involving crafted OCI architecture name=
s.
       A malicious local user on a system with an OCI remote configured
       (unusual on non-Fedora systems) could trick the flatpak-system-helper
       process into writing outside /var/lib/flatpak.
     - d/p/GHSA-w69g-9x8j-7p8f/*.patch:
       Fix reading outside sandbox involving crafted extension metadata.
       A malicious or compromised Flatpak app could find out whether specific
       files exist outside the sandbox.
     - d/p/GHSA-q4gr-vc25-57m5/*.patch:
       Fix anti-downgrade checks for components installed system-wide.
       A malicious local user with an active local login session could
       downgrade an app, runtime or extension to an older, known-vulnerable
       version and use this to attack other local users.
     - d/p/GHSA-jr92-2v97-wgvc/*.patch:
       Fix a buffer overflow when installing or updating from a malicious OCI
       registry, not believed to be practically exploitable on 64-bit systems.
     - d/p/hardening/*.patch:
       Harden file accesses against path traversal, fixing issues that
       were initially thought to be security vulnerabilities similar to
       those above, but on further analysis do not seem to be exploitable.
     - d/p/GHSA-r7hp-698j-2h6c/*.patch:
       Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts
       so that GTK accessibility features work as intended.
       Previously, these accessibility features only worked accidentally as a
       result of an xdg-dbus-proxy security issue, fixed in 0.1.8.
   * d/patches: Add additional bug fixes from upstream 1.16.x branch
     - d/p/subprojects-Ignore-.wraplock-file-generated-by-recent-Mes.patch,
       d/p/bwrap-Clarify-a-comment.patch,
       d/p/subprojects-Update-dbus-proxy.wrap-to-v0.1.7.patch:
       Resync with upstream source, no functional changes
     - d/p/dir-Use-flatpak_bwrap_child_setup_inherit_fds_cb-to-apply.patch:
       Silence a spurious warning when apps use the extra_data mechanism
     - d/p/portal-Actually-use-the-AppInfo-hash-table.patch:
       Fix a memory leak and potential rare crashes in flatpak-portal
Checksums-Sha1:
 23819bb80df3336957c6a48b2d9e8b8cb2d47237 3741 flatpak_1.16.6-1~deb13u2.dsc
 ba597a6fe31a0749cb3f8835b72885e5b235b9d2 76448 flatpak_1.16.6-1~deb13u2.debi=
an.tar.xz
 131e098bbf4d64f1f69a4ceb55f12949f12b4b87 15293 flatpak_1.16.6-1~deb13u2_sour=
ce.buildinfo
Checksums-Sha256:
 5aa8c6319336226ac6638acd8df94b63bc27da4621a478f3e47e0f9f564c18de 3741 flatpa=
k_1.16.6-1~deb13u2.dsc
 bac37dc8430afe688734263f7efecb8a9bfff6098011d24a1647b2f09c99d790 76448 flatp=
ak_1.16.6-1~deb13u2.debian.tar.xz
 cd3a79eddc583a2c65b61a71f05b936bef12a05362d5caa2233b3e1ed7bf00f6 15293 flatp=
ak_1.16.6-1~deb13u2_source.buildinfo
Files:
 4ca674bfa72b7210851606ff843ed90e 3741 admin optional flatpak_1.16.6-1~deb13u=
2.dsc
 51eeccf1f9d601f93a4a2ca595a714fe 76448 admin optional flatpak_1.16.6-1~deb13=
u2.debian.tar.xz
 c295c3e06eaf5d5e5a86cfe665b6a27c 15293 admin optional flatpak_1.16.6-1~deb13=
u2_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmp7OMQACgkQI1wJnT6z
MHbM7BAAyWAr40Kt7lpDvCJmkCS1LcRTBexSBmchq8rrP0yeLQwoJ3KynC0lI7FO
ZhwhmnqCeBu+s0X5dH409FYGV8SimHLWw7ihPnnqZUvc0bjEGidanULENxnb3r2G
v5r6RrI93xUZDVkR3ZyrHBUV4i4WSZJD9dMKf91UWuFh2InPz2edIhi86nRkZSox
r4VDn6/AArAJ5yfBOeV001AUOGwFVvCmzZzYmys1Bl0aTtHDeJrZu7aE3JIsf1li
AeHxN7sul1Ti3hqtlglL7ISVsdNycgqqU8T4osTDDfOU5Xk2yGk97yePRuZ1Du4I
p5h+3IWAQMoOsZy3eYnKALiObqtGmW8iZw4SYLdNOtPLmmlynvbcfffoEe6r9JCz
3ONRXTmu6KpwQFXVPx0oAN9z0sz8ynA8SeXxg4Q0YfsVA/+cT6PdAfzNezvFbEM8
yYn4MOgi3iI5XPx9UG2ecitUZAPjRbG3py7ey9k3qVuP7XcvI28umZ0opPPjHCZ9
AHZmIQHz9WYHsJSGxI8cvXgNYDp4SCSk3KWfj0Go+q/wvRW00FYW+2AiKELuNauN
vY/cgKw4/xorvUYTzBRoy3e2YD0QHbAYgW6Z9UbxKgyp1gpeW9nxim8nNYFlPooK
EVVffgpmXh8hX/FvX57s5/tZ7qzeVHN/uu4hqv4QdorQgW/rVRs=3D
=3Dd3BX
-----END PGP SIGNATURE-----


--===============5104066808550732804==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCaohW8QAKCRCb9qggYcy5
Iba/AP9HLLlsSDmyzUCbMtKu4mcEKAMYI6fJ9txqT+ZcSIVT2QEAq6/HAzdojx/w
kI49KLoCNkH3pl3cZVYpK3D2/uzQqwU=
=Eir8
-----END PGP SIGNATURE-----

--===============5104066808550732804==--
]