[Pkg-utopia-maintainers] Bug#1144130: flatpak: multiple vulnerabilities fixed by 1.18.1

Simon McVittie smcv at debian.org
Tue Aug 11 14:50:41 BST 2026


On Tue, 11 Aug 2026 at 13:32:05 +0100, Simon McVittie wrote:
>This bug report is a placeholder for all of the vulnerabilities that are
>fixed in prerelease 1.19.0. The same vulnerabilities will also be fixed
>in a 1.18.1 stable release, soon. More details when they are available.

https://github.com/flatpak/flatpak/releases/tag/1.18.1 lists all the 
vulnerabilities. We don't have CVE IDs for any of them yet, so they're 
referenced by GHSA- IDs.

The most serious are a full sandbox escape (GHSA-8688-9x26-hhxj) and 
local root privilege escalation (GHSA-qrwq-7qwx-q9rp, GHSA-fqx6-vh4p-42cg).

I will upload 1.18.1 to unstable soon: automated tests are still 
running, but manual testing was successful.

All of the vulnerabilities except for GHSA-9rww-v4mm-x4jg affect trixie 
as well. GHSA-9rww-v4mm-x4jg is a problem with a new feature that was 
added in the 1.17.x/1.18.x cycle, so trixie is not vulnerable to it.

https://people.debian.org/~smcv/bug1144130/trixie/ contains backported 
fixes for trixie, covering everything except GHSA-9rww-v4mm-x4jg. As 
discussed by private email with the security team, this also includes 
pending upstream non-security bug fixes from the flatpak-1.16.x branch. 
May I upload?

For convenience, https://people.debian.org/~smcv/bug1144130/trixie/rc/ 
contains source and amd64 binaries for a functionally equivalent 
test-build (the only difference is the changelog).

Thanks,
     smcv



More information about the Pkg-utopia-maintainers mailing list