[Pkg-utopia-maintainers] flatpak_1.16.6-1~deb13u3_source.changes ACCEPTED into proposed-updates->stable-new
Debian FTP Masters
ftpmaster at ftp-master.debian.org
Mon Sep 28 19:34:09 BST 2026
Thank you for your contribution to Debian.
Mapping stable-security to proposed-updates.
Accepted:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 28 Sep 2026 14:13:01 +0100
Source: flatpak
Architecture: source
Version: 1.16.6-1~deb13u3
Distribution: trixie-security
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers at lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv at debian.org>
Closes: 1149218
Changes:
flatpak (1.16.6-1~deb13u3) trixie-security; urgency=high
.
* d/patches: Backport security fixes from 1.18.4 (Closes: #1149218):
- Fix two related symlink traversal vulnerabilities to prevent arbitrary
file deletion and limited file overwriting outside the deploy
directory, and harden related code paths against symlink traversal
(deletion: CVE-2026-97023, GHSA-5p67-xh8x-rq54)
(overwriting: CVE-2026-97024, GHSA-8xgq-v545-vgvf)
- When using OCI remotes, don't make authentication token readable by
other users
(CVE-2026-97025, GHSA-7rvf-rqr3-43j4)
- Restrict permissions of temporary directories /var/tmp/flatpak-cache-*
(CVE-2026-97026, GHSA-r9w3-qx54-qvc8)
- Filter D-Bus .service files and freedesktop.org .desktop files
with an allowlist to prevent denial of service and possibly
sandbox escape
(CVE-2026-97027, GHSA-v64f-hrwr-j4vh)
- Prevent sandboxed processes from killing a parent process outside the
sandbox
(CVE-2026-97029, GHSA-f3p8-vr7v-gxf2)
* Mention CVE-2026-90616, CVE-2026-92162 in previous changelog entry
Checksums-Sha1:
f72674b664b1c7c111c6648d098e11952982f536 3741 flatpak_1.16.6-1~deb13u3.dsc
b6d693e6c8de02f7fa16821645c8bc38172dfbc3 86412 flatpak_1.16.6-1~deb13u3.debian.tar.xz
e88ee46b27a06247220e7ef2f7214ea04a12105f 15479 flatpak_1.16.6-1~deb13u3_source.buildinfo
Checksums-Sha256:
5f4bb9d94e039f6c0c35c28b22b2d0f6030b6d83560d8c80996c399a7a43b142 3741 flatpak_1.16.6-1~deb13u3.dsc
21cf5dbf20f453f007476322f864552b45a0f8521d86b907c7a015fba82141ac 86412 flatpak_1.16.6-1~deb13u3.debian.tar.xz
a7a6bb191854b17889c755b5f30bf83116897f76f114ca9f8e7e259933a3ec82 15479 flatpak_1.16.6-1~deb13u3_source.buildinfo
Files:
f03cade7037f07cc784b8a261c6cc7d0 3741 admin optional flatpak_1.16.6-1~deb13u3.dsc
10f95f8be7b5fef7889275e0fd2c0ec2 86412 admin optional flatpak_1.16.6-1~deb13u3.debian.tar.xz
5be08845ca189203fc6f123b924513e9 15479 admin optional flatpak_1.16.6-1~deb13u3_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmq6bjgACgkQI1wJnT6z
MHYH6Q//bnRqvZaYgiWNVLUeK8WN8L8K2IJXRsUfhEwUhNQP+mB8AL6buz9s0Mfy
rJfrGsKvgq61Z6S0JMs9zNUPHVvqh+fT4mjJ+Z+8r9jLjjumsIQqdhHFlDSVGKzQ
0hc2K665Zc5Y+eIHHx3K0zrNzfiwCrnTkxvDRB110NGQdspcDGKf1koBN7fXCJb3
znEQDwNFwTDYd7QqfNl1lNs327cPZnS6MDsxJFCBWplS/kLvbiGAZ8RdJH5IyYkq
xtdRgsxT/xkKu+WnnLXvbyeBaxWAyPPXYYhf/kcYgHDEU2GHy1BfD7o1+0ueBJVf
VWLltG+2jy/OHFcKm8d6Xky2rT6PBiInpwxscJTk0K/23nxEXGEpwmtFVHxDgcP9
1/dkBUIiyCfSUj5lxiRAXVaYhCFyoPi6K3IW5iy6Tzj9Y21N0IqAtmeqwc6y8WVh
GnCQT1C/J25FisFGFYdgPP0k73Krj7/zCRA72iU1w2nksx+SerRnDOgeXswpL2+L
jqzwjm/ki/5wfkVONaobCC63F8tCybmcOqZ8Q7RC8+xQ/TYsJoufB4loQOgRWg3P
IW11em3DagI5bZb44VuCloQxg9qgkdq6HXOTDkgUFVHKIUDDfZy97Vc6hKRMNawK
LuwCSychmxMfljRwEkR/DQWFdbx+xaKU24loMF0UOb9df7lZ068=
=ihbl
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-utopia-maintainers/attachments/20260928/fc5994da/attachment.sig>
More information about the Pkg-utopia-maintainers
mailing list