[Pkg-utopia-maintainers] flatpak_1.18.1-1_source.changes ACCEPTED into unstable

Debian FTP Masters ftpmaster at ftp-master.debian.org
Tue Aug 11 15:20:04 BST 2026


Thank you for your contribution to Debian.



Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 11 Aug 2026 14:02:52 +0100
Source: flatpak
Architecture: source
Version: 1.18.1-1
Distribution: unstable
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers at lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv at debian.org>
Closes: 1144130
Changes:
 flatpak (1.18.1-1) unstable; urgency=high
 .
   * New upstream security fix release (Closes: #1144130)
     - GHSA-fqx6-vh4p-42cg:
       Fix writing outside installation directory via crafted commit metadata.
       A malicious or compromised Flatpak repository could write
       attacker-controlled files outside /var/lib/flatpak as root.
     - GHSA-qrwq-7qwx-q9rp:
       Fix local privilege escalation involving revokefs.
       A malicious local user could write files outside /var/lib/flatpak
       as root by tampering with OSTree objects after signature verification.
     - GHSA-8688-9x26-hhxj:
       Fix a sandbox escape involving directories inside ~/.var/app/APP_ID.
       A malicious or compromised Flatpak app could write to arbitrary files
       outside its sandbox.
     - GHSA-99wv-m8rp-g58x:
       Fix a sandbox escape involving the ld.so cache.
       A malicious or compromised Flatpak app could write files with a fixed
       name and limited control over content outside the sandbox.
     - GHSA-v2gw-v9h5-9q4x:
       Fix local privilege escalation involving crafted OCI architecture names.
       A malicious local user on a system with an OCI remote configured
       (unusual on non-Fedora systems) could trick the flatpak-system-helper
       process into writing outside /var/lib/flatpak.
     - GHSA-w69g-9x8j-7p8f:
       Fix reading outside sandbox involving crafted extension metadata.
       A malicious or compromised Flatpak app could find out whether specific
       files exist outside the sandbox.
     - GHSA-q4gr-vc25-57m5:
       Fix anti-downgrade checks for components installed system-wide.
       A malicious local user with an active local login session could
       downgrade an app, runtime or extension to an older, known-vulnerable
       version and use this to attack other local users.
     - GHSA-8qxj-x646-phcm:
       Fix writing outside working directory in `flatpak build-init`.
       A malicious or compromised SDK could write outside the intended
       working directory when a developer starts using it for a build.
     - GHSA-jr92-2v97-wgvc:
       Fix a buffer overflow when installing or updating from a malicious OCI
       registry, not believed to be practically exploitable on 64-bit systems.
     - GHSA-r7hp-698j-2h6c:
       Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts
       so that GTK accessibility features work as intended.
       Previously, these accessibility features only worked accidentally as a
       result of an xdg-dbus-proxy security issue, fixed in 0.1.8.
     - Numerous non-security-related bug fixes
Checksums-Sha1:
 1c03d09f22fdec31cb75c907e1daf7a952bd6790 4057 flatpak_1.18.1-1.dsc
 f2378fd645e7fcf41e8f67849fadaecec613c22a 1355712 flatpak_1.18.1.orig.tar.xz
 7fe64816a3b19373b6d6f6203a4e62e7f01cc04d 43804 flatpak_1.18.1-1.debian.tar.xz
 61da1b8d64264fda5ff3f1c40db05129e8dea988 4650296 flatpak_1.18.1-1.git.tar.xz
 79cabf2eca03415941e8eabaa0ab245232206862 17556 flatpak_1.18.1-1_source.buildinfo
Checksums-Sha256:
 84b0a6ec350cd934f60e5c21b0d0727a9d90e209fe59e7f2cbf7ced32fde93fc 4057 flatpak_1.18.1-1.dsc
 bc683fc916ed21c0524bb064f358c2ac18586b8ec88c76f2f7f289877521631c 1355712 flatpak_1.18.1.orig.tar.xz
 e863fbe3457dc2568b4ca5de3eef841c7e98813b98b3aa2476844224edf19454 43804 flatpak_1.18.1-1.debian.tar.xz
 dbc43065ffcea6da750db2fb8e1623ed97efce280edf2db21f1e6122f4c12b82 4650296 flatpak_1.18.1-1.git.tar.xz
 3297b278511c08405e158be5ca2ca786f0ed08310a5fef31afae5fd89a0f2440 17556 flatpak_1.18.1-1_source.buildinfo
Files:
 776f43644f37db94e2837fc21ab56c5d 4057 admin optional flatpak_1.18.1-1.dsc
 f20f8b81b9bc979db057a9c2e717cf14 1355712 admin optional flatpak_1.18.1.orig.tar.xz
 e9d937a99d198ced639b6be170bfb6f9 43804 admin optional flatpak_1.18.1-1.debian.tar.xz
 b208d76105c10118cb33bc0d3f5d3b03 4650296 admin None flatpak_1.18.1-1.git.tar.xz
 c8906ee405d6a801b53f306b54832d4a 17556 admin optional flatpak_1.18.1-1_source.buildinfo
Git-Tag-Info: tag=f6dbe0ad231a7a761f823ef3c062a237a02cab7f fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <smcv at debian.org>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmp7K0wACgkQYG0ITkaD
wHnfeQ//YweEOLWaN7D+pFQf/4AfSCvSgGF//of7pv1dZbFHLWs1FW4hYlXZ814t
Br4TW4xLRWCrLCezYq1sWMf9Sp0JQgK+mrP/0YlRos6IaV0P4NTzyCyd6+kcx06s
ieIWMVew99fvKt/kvmVUIwAv3idekq2dx/UBUlJMJEVDcSVfPKEJYWEt2tIsNt+V
rt2owh/kxiy1Rulj3ozTjUMk4qnssmn+K33vGdwF4Y1sKeByCiZbD/TQgzlUBkp5
+nIwj+Cr7Rk/bxhmSAC2bCw0YeuhWizQXyEsM3/0I7CiYosGF43j576F7PXVAABQ
988W6U9AKHC9aPvXbASHrrJKgLRz3rIfxs9M9jsYiACfgwvmUZ276UrY1968/e/d
TSIwNlwW6ISJfRrhQCzcWoqlzxyO19QsQ3N9TFU/X0DLSEF/lpg5DS/C7NgxnyWI
SZrMqcTaRteSWKtAHBC5+EI2kNyBqgwDX7UGrGksqmpQAMpdPhoV2ll2p7wOF647
C5DB8DqRfPkvmI7kmeg+/hp4z7Au8K7P4dcQEDxB7DX2y8T1JU09lb+kWq8AQFZU
dCBGlS0bzGg96naxsER1zwIazMp2cMthIjr2hI/luO/5CBnZJ675NkLERQmzWhs0
gWNumUiBo7Tzy8uXybyTG6Ag+gyAdns/t9xjW+J4A5KWamPkCTo=
=BU4P
-----END PGP SIGNATURE-----

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-utopia-maintainers/attachments/20260811/584467c4/attachment-0001.sig>


More information about the Pkg-utopia-maintainers mailing list