[Pkg-utopia-maintainers] Bug#1144130: flatpak: multiple vulnerabilities fixed by 1.18.1

Salvatore Bonaccorso carnil at debian.org
Tue Aug 11 15:42:04 BST 2026


Hi Simon,

On Tue, Aug 11, 2026 at 02:50:41PM +0100, Simon McVittie wrote:
> On Tue, 11 Aug 2026 at 13:32:05 +0100, Simon McVittie wrote:
> > This bug report is a placeholder for all of the vulnerabilities that are
> > fixed in prerelease 1.19.0. The same vulnerabilities will also be fixed
> > in a 1.18.1 stable release, soon. More details when they are available.
> 
> https://github.com/flatpak/flatpak/releases/tag/1.18.1 lists all the
> vulnerabilities. We don't have CVE IDs for any of them yet, so they're
> referenced by GHSA- IDs.
> 
> The most serious are a full sandbox escape (GHSA-8688-9x26-hhxj) and local
> root privilege escalation (GHSA-qrwq-7qwx-q9rp, GHSA-fqx6-vh4p-42cg).
> 
> I will upload 1.18.1 to unstable soon: automated tests are still running,
> but manual testing was successful.
> 
> All of the vulnerabilities except for GHSA-9rww-v4mm-x4jg affect trixie as
> well. GHSA-9rww-v4mm-x4jg is a problem with a new feature that was added in
> the 1.17.x/1.18.x cycle, so trixie is not vulnerable to it.
> 
> https://people.debian.org/~smcv/bug1144130/trixie/ contains backported fixes
> for trixie, covering everything except GHSA-9rww-v4mm-x4jg. As discussed by
> private email with the security team, this also includes pending upstream
> non-security bug fixes from the flatpak-1.16.x branch. May I upload?

Yes please do upload to security-master (just confirming, you should
already have an ack from Moritz on the flatpak update).

Regards,
Salvatore



More information about the Pkg-utopia-maintainers mailing list