[Pkg-utopia-maintainers] Bug#1144130: flatpak: multiple vulnerabilities fixed by 1.18.1
Simon McVittie
smcv at debian.org
Tue Aug 11 14:50:41 BST 2026
On Tue, 11 Aug 2026 at 13:32:05 +0100, Simon McVittie wrote:
>This bug report is a placeholder for all of the vulnerabilities that are
>fixed in prerelease 1.19.0. The same vulnerabilities will also be fixed
>in a 1.18.1 stable release, soon. More details when they are available.
https://github.com/flatpak/flatpak/releases/tag/1.18.1 lists all the
vulnerabilities. We don't have CVE IDs for any of them yet, so they're
referenced by GHSA- IDs.
The most serious are a full sandbox escape (GHSA-8688-9x26-hhxj) and
local root privilege escalation (GHSA-qrwq-7qwx-q9rp, GHSA-fqx6-vh4p-42cg).
I will upload 1.18.1 to unstable soon: automated tests are still
running, but manual testing was successful.
All of the vulnerabilities except for GHSA-9rww-v4mm-x4jg affect trixie
as well. GHSA-9rww-v4mm-x4jg is a problem with a new feature that was
added in the 1.17.x/1.18.x cycle, so trixie is not vulnerable to it.
https://people.debian.org/~smcv/bug1144130/trixie/ contains backported
fixes for trixie, covering everything except GHSA-9rww-v4mm-x4jg. As
discussed by private email with the security team, this also includes
pending upstream non-security bug fixes from the flatpak-1.16.x branch.
May I upload?
For convenience, https://people.debian.org/~smcv/bug1144130/trixie/rc/
contains source and amd64 binaries for a functionally equivalent
test-build (the only difference is the changelog).
Thanks,
smcv
More information about the Pkg-utopia-maintainers
mailing list