[From nobody Mon Sep 28 14:37:08 2026
Received: (at submit) by bugs.debian.org; 28 Sep 2026 13:02:56 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-107.3 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIMWL_WL_HIGH,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,
 FOURLA,FROMDEVELOPER,FVGT_m_MULTI_ODD,SPF_HELO_NONE,SPF_PASS,
 USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 51; hammy, 150; neutral, 76; spammy,
 0. spammytokens:
 hammytokens:0.000-+--Hx-spam-relays-external:sk:stravin,
 0.000-+--H*RT:sk:stravin, 0.000-+--Hx-spam-relays-external:311,
 0.000-+--H*RT:311, 0.000-+--H*RT:108
Return-path: &lt;smcv@debian.org&gt;
Received: from stravinsky.debian.org ([2001:41b8:202:deb::311:108]:56532)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;smcv@debian.org&gt;) id 1xBB0S-007noh-06
 for submit@bugs.debian.org; Mon, 28 Sep 2026 13:02:56 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; 
 s=smtpauto.stravinsky;
 h=X-Debian-User:Content-Transfer-Encoding:Content-Type
 :MIME-Version:Message-ID:Subject:To:From:Date:Reply-To:Cc:Content-ID:
 Content-Description:In-Reply-To:References;
 bh=hHD6x6HxwiI6oIk8dJTCDjCCSQPbMOqCixvb6UHMiS0=; b=pgwSo7T8OvWH9HEQT3krNrR/Zy
 YaM1OeIaPUZgH7v3CCg9RuWkfg0Nzoza8ItjwXuOPJ2mdcyzML+R6Kln53crC0cWrtGVjg04AGpFd
 sR+l6bOxwFJpRNJHUA+1MST7HPc0ZTA/fz1gY0LDhJkBKWscyVjLs0cT131oe69ICfVuo2Ukcvbvt
 2bTLsQdjHDxxRNUddL5DNrDWomPDn45LsIVheogkxGLNWJV21a9BJTqSpO1R24y23nzMetsH8QUTe
 vPfIf+pDcZfcbJyX67IyidpCzkw2AFSykCOd5enqSpTjw7s3BKwpl14IvWfpsOWK7IcZCcFm1nlJL
 7ynWWwQg==;
Received: from authenticated-user by stravinsky.debian.org with esmtpsa
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;smcv@debian.org&gt;) id 1xBB0L-007drR-1F
 for submit@bugs.debian.org; Mon, 28 Sep 2026 13:02:49 +0000
Date: Mon, 28 Sep 2026 14:02:44 +0100
From: Simon McVittie &lt;smcv@debian.org&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: flatpak: multiple vulnerabilities fixed in 1.18.4
Message-ID: &lt;arpldAB2xbze3bfd@definition.pseudorandom.co.uk&gt;
MIME-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
X-Mutt-Fcc: =.lists.debian/
X-Reportbug-Version: 13.2.0+nmu1
X-Debian-User: smcv
Delivered-To: submit@bugs.debian.org

Source: flatpak
Severity: grave
Tags: security
Justification: user security hole
X-Debbugs-Cc: Debian Security Team &lt;team@security.debian.org&gt;

Flatpak 1.18.4 addresses multiple security vulnerabilities:

&gt;* Prevent privileged overwrite of arbitrary files with an empty file or a
&gt;  symlink to /run/host/monitor/resolv.conf when a malicious app is installed
&gt;  (CVE-2026-97024, GHSA-8xgq-v545-vgvf; thanks to Sebastian Wick)
&gt;
&gt;* Prevent privileged deletion of arbitrary files when a malicious app
&gt;  is installed
&gt;  (CVE-2026-97023, GHSA-5p67-xh8x-rq54; thanks to Sebastian Wick)
&gt;
&gt;* When downloading apps or runtimes from an OCI repository that requires
&gt;  authentication, don't make the authentication token visible to other users
&gt;  (CVE-2026-97025, GHSA-7rvf-rqr3-43j4; thanks to AISLE in cooperation
&gt;  with Red Hat)
&gt;
&gt;* Restrict permissions on temporary repository directories in
&gt;  /var/tmp/flatpak-cache-*
&gt;  (CVE-2026-97026, GHSA-r9w3-qx54-qvc8; thanks to AISLE in cooperation
&gt;  with Red Hat)
&gt;
&gt;* Filter .desktop and D-Bus .service files against an allowlist of fields,
&gt;  preventing denial of service and unintended interactions with host services
&gt;  (CVE-2026-97027, GHSA-v64f-hrwr-j4vh; thanks to Markus Göllnitz)
&gt;
&gt;* Prevent apps from sending signals to a process group that includes a
&gt;  parent process outside the app, causing denial of service by killing
&gt;  the desktop environment
&gt;  (CVE-2026-97029, GHSA-f3p8-vr7v-gxf2; thanks to Guthrie Armstrong,
&gt;  Coalition, Inc.)

I intend to fix these as a batch, in both testing/unstable and stable, 
so reporting one bug for the whole batch.

    smcv
]