[Pkg-utopia-maintainers] flatpak_1.16.6-1~deb13u2_source.changes ACCEPTED into proposed-updates->stable-new

Debian FTP Masters ftpmaster at ftp-master.debian.org
Wed Aug 12 19:20:13 BST 2026


Thank you for your contribution to Debian.

Mapping stable-security to proposed-updates.

Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 11 Aug 2026 14:03:38 +0100
Source: flatpak
Architecture: source
Version: 1.16.6-1~deb13u2
Distribution: trixie-security
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers at lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv at debian.org>
Closes: 1144130
Changes:
 flatpak (1.16.6-1~deb13u2) trixie-security; urgency=high
 .
   * d/patches: Backport security fixes from 1.18.1 (Closes: #1144130)
     - d/p/libglnx/*.patch:
       Backport glnx_chase_and_mkdirat() utility function, required by some
       of the security fixes below
     - d/p/tests/*.patch:
       Backport unit tests fixes which are required by the tests for some
       of the security fixes below
     - d/p/GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/*.patch:
       + GHSA-fqx6-vh4p-42cg:
         Fix writing outside installation directory via crafted commit metadata.
         A malicious or compromised Flatpak repository could write
         attacker-controlled files outside /var/lib/flatpak as root.
       + GHSA-8qxj-x646-phcm:
         Fix writing outside working directory in `flatpak build-init`.
         A malicious or compromised SDK could write outside the intended
         working directory when a developer starts using it for a build.
     - d/p/GHSA-qrwq-7qwx-q9rp/*.patch:
       Fix local privilege escalation involving revokefs.
       A malicious local user could write files outside /var/lib/flatpak
       as root by tampering with OSTree objects after signature verification.
     - d/p/GHSA-8688-9x26-hhxj/*.patch:
       Fix a sandbox escape involving directories inside ~/.var/app/APP_ID.
       A malicious or compromised Flatpak app could write to arbitrary files
       outside its sandbox.
     - d/p/GHSA-99wv-m8rp-g58x/*.patch:
       Fix a sandbox escape involving the ld.so cache.
       A malicious or compromised Flatpak app could write files with a fixed
       name and limited control over content outside the sandbox.
     - d/p/GHSA-v2gw-v9h5-9q4x/*.patch:
       Fix local privilege escalation involving crafted OCI architecture names.
       A malicious local user on a system with an OCI remote configured
       (unusual on non-Fedora systems) could trick the flatpak-system-helper
       process into writing outside /var/lib/flatpak.
     - d/p/GHSA-w69g-9x8j-7p8f/*.patch:
       Fix reading outside sandbox involving crafted extension metadata.
       A malicious or compromised Flatpak app could find out whether specific
       files exist outside the sandbox.
     - d/p/GHSA-q4gr-vc25-57m5/*.patch:
       Fix anti-downgrade checks for components installed system-wide.
       A malicious local user with an active local login session could
       downgrade an app, runtime or extension to an older, known-vulnerable
       version and use this to attack other local users.
     - d/p/GHSA-jr92-2v97-wgvc/*.patch:
       Fix a buffer overflow when installing or updating from a malicious OCI
       registry, not believed to be practically exploitable on 64-bit systems.
     - d/p/hardening/*.patch:
       Harden file accesses against path traversal, fixing issues that
       were initially thought to be security vulnerabilities similar to
       those above, but on further analysis do not seem to be exploitable.
     - d/p/GHSA-r7hp-698j-2h6c/*.patch:
       Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts
       so that GTK accessibility features work as intended.
       Previously, these accessibility features only worked accidentally as a
       result of an xdg-dbus-proxy security issue, fixed in 0.1.8.
   * d/patches: Add additional bug fixes from upstream 1.16.x branch
     - d/p/subprojects-Ignore-.wraplock-file-generated-by-recent-Mes.patch,
       d/p/bwrap-Clarify-a-comment.patch,
       d/p/subprojects-Update-dbus-proxy.wrap-to-v0.1.7.patch:
       Resync with upstream source, no functional changes
     - d/p/dir-Use-flatpak_bwrap_child_setup_inherit_fds_cb-to-apply.patch:
       Silence a spurious warning when apps use the extra_data mechanism
     - d/p/portal-Actually-use-the-AppInfo-hash-table.patch:
       Fix a memory leak and potential rare crashes in flatpak-portal
Checksums-Sha1:
 23819bb80df3336957c6a48b2d9e8b8cb2d47237 3741 flatpak_1.16.6-1~deb13u2.dsc
 ba597a6fe31a0749cb3f8835b72885e5b235b9d2 76448 flatpak_1.16.6-1~deb13u2.debian.tar.xz
 131e098bbf4d64f1f69a4ceb55f12949f12b4b87 15293 flatpak_1.16.6-1~deb13u2_source.buildinfo
Checksums-Sha256:
 5aa8c6319336226ac6638acd8df94b63bc27da4621a478f3e47e0f9f564c18de 3741 flatpak_1.16.6-1~deb13u2.dsc
 bac37dc8430afe688734263f7efecb8a9bfff6098011d24a1647b2f09c99d790 76448 flatpak_1.16.6-1~deb13u2.debian.tar.xz
 cd3a79eddc583a2c65b61a71f05b936bef12a05362d5caa2233b3e1ed7bf00f6 15293 flatpak_1.16.6-1~deb13u2_source.buildinfo
Files:
 4ca674bfa72b7210851606ff843ed90e 3741 admin optional flatpak_1.16.6-1~deb13u2.dsc
 51eeccf1f9d601f93a4a2ca595a714fe 76448 admin optional flatpak_1.16.6-1~deb13u2.debian.tar.xz
 c295c3e06eaf5d5e5a86cfe665b6a27c 15293 admin optional flatpak_1.16.6-1~deb13u2_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmp7OMQACgkQI1wJnT6z
MHbM7BAAyWAr40Kt7lpDvCJmkCS1LcRTBexSBmchq8rrP0yeLQwoJ3KynC0lI7FO
ZhwhmnqCeBu+s0X5dH409FYGV8SimHLWw7ihPnnqZUvc0bjEGidanULENxnb3r2G
v5r6RrI93xUZDVkR3ZyrHBUV4i4WSZJD9dMKf91UWuFh2InPz2edIhi86nRkZSox
r4VDn6/AArAJ5yfBOeV001AUOGwFVvCmzZzYmys1Bl0aTtHDeJrZu7aE3JIsf1li
AeHxN7sul1Ti3hqtlglL7ISVsdNycgqqU8T4osTDDfOU5Xk2yGk97yePRuZ1Du4I
p5h+3IWAQMoOsZy3eYnKALiObqtGmW8iZw4SYLdNOtPLmmlynvbcfffoEe6r9JCz
3ONRXTmu6KpwQFXVPx0oAN9z0sz8ynA8SeXxg4Q0YfsVA/+cT6PdAfzNezvFbEM8
yYn4MOgi3iI5XPx9UG2ecitUZAPjRbG3py7ey9k3qVuP7XcvI28umZ0opPPjHCZ9
AHZmIQHz9WYHsJSGxI8cvXgNYDp4SCSk3KWfj0Go+q/wvRW00FYW+2AiKELuNauN
vY/cgKw4/xorvUYTzBRoy3e2YD0QHbAYgW6Z9UbxKgyp1gpeW9nxim8nNYFlPooK
EVVffgpmXh8hX/FvX57s5/tZ7qzeVHN/uu4hqv4QdorQgW/rVRs=
=d3BX
-----END PGP SIGNATURE-----

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-utopia-maintainers/attachments/20260812/42a0cb01/attachment-0001.sig>


More information about the Pkg-utopia-maintainers mailing list