[Pkg-utopia-maintainers] flatpak_1.16.6-1~deb13u3_source.changes ACCEPTED into proposed-updates->stable-new

Debian FTP Masters ftpmaster at ftp-master.debian.org
Mon Sep 28 19:34:09 BST 2026


Thank you for your contribution to Debian.

Mapping stable-security to proposed-updates.

Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 28 Sep 2026 14:13:01 +0100
Source: flatpak
Architecture: source
Version: 1.16.6-1~deb13u3
Distribution: trixie-security
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers at lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv at debian.org>
Closes: 1149218
Changes:
 flatpak (1.16.6-1~deb13u3) trixie-security; urgency=high
 .
   * d/patches: Backport security fixes from 1.18.4 (Closes: #1149218):
     - Fix two related symlink traversal vulnerabilities to prevent arbitrary
       file deletion and limited file overwriting outside the deploy
       directory, and harden related code paths against symlink traversal
       (deletion: CVE-2026-97023, GHSA-5p67-xh8x-rq54)
       (overwriting: CVE-2026-97024, GHSA-8xgq-v545-vgvf)
     - When using OCI remotes, don't make authentication token readable by
       other users
       (CVE-2026-97025, GHSA-7rvf-rqr3-43j4)
     - Restrict permissions of temporary directories /var/tmp/flatpak-cache-*
       (CVE-2026-97026, GHSA-r9w3-qx54-qvc8)
     - Filter D-Bus .service files and freedesktop.org .desktop files
       with an allowlist to prevent denial of service and possibly
       sandbox escape
       (CVE-2026-97027, GHSA-v64f-hrwr-j4vh)
     - Prevent sandboxed processes from killing a parent process outside the
       sandbox
       (CVE-2026-97029, GHSA-f3p8-vr7v-gxf2)
   * Mention CVE-2026-90616, CVE-2026-92162 in previous changelog entry
Checksums-Sha1:
 f72674b664b1c7c111c6648d098e11952982f536 3741 flatpak_1.16.6-1~deb13u3.dsc
 b6d693e6c8de02f7fa16821645c8bc38172dfbc3 86412 flatpak_1.16.6-1~deb13u3.debian.tar.xz
 e88ee46b27a06247220e7ef2f7214ea04a12105f 15479 flatpak_1.16.6-1~deb13u3_source.buildinfo
Checksums-Sha256:
 5f4bb9d94e039f6c0c35c28b22b2d0f6030b6d83560d8c80996c399a7a43b142 3741 flatpak_1.16.6-1~deb13u3.dsc
 21cf5dbf20f453f007476322f864552b45a0f8521d86b907c7a015fba82141ac 86412 flatpak_1.16.6-1~deb13u3.debian.tar.xz
 a7a6bb191854b17889c755b5f30bf83116897f76f114ca9f8e7e259933a3ec82 15479 flatpak_1.16.6-1~deb13u3_source.buildinfo
Files:
 f03cade7037f07cc784b8a261c6cc7d0 3741 admin optional flatpak_1.16.6-1~deb13u3.dsc
 10f95f8be7b5fef7889275e0fd2c0ec2 86412 admin optional flatpak_1.16.6-1~deb13u3.debian.tar.xz
 5be08845ca189203fc6f123b924513e9 15479 admin optional flatpak_1.16.6-1~deb13u3_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmq6bjgACgkQI1wJnT6z
MHYH6Q//bnRqvZaYgiWNVLUeK8WN8L8K2IJXRsUfhEwUhNQP+mB8AL6buz9s0Mfy
rJfrGsKvgq61Z6S0JMs9zNUPHVvqh+fT4mjJ+Z+8r9jLjjumsIQqdhHFlDSVGKzQ
0hc2K665Zc5Y+eIHHx3K0zrNzfiwCrnTkxvDRB110NGQdspcDGKf1koBN7fXCJb3
znEQDwNFwTDYd7QqfNl1lNs327cPZnS6MDsxJFCBWplS/kLvbiGAZ8RdJH5IyYkq
xtdRgsxT/xkKu+WnnLXvbyeBaxWAyPPXYYhf/kcYgHDEU2GHy1BfD7o1+0ueBJVf
VWLltG+2jy/OHFcKm8d6Xky2rT6PBiInpwxscJTk0K/23nxEXGEpwmtFVHxDgcP9
1/dkBUIiyCfSUj5lxiRAXVaYhCFyoPi6K3IW5iy6Tzj9Y21N0IqAtmeqwc6y8WVh
GnCQT1C/J25FisFGFYdgPP0k73Krj7/zCRA72iU1w2nksx+SerRnDOgeXswpL2+L
jqzwjm/ki/5wfkVONaobCC63F8tCybmcOqZ8Q7RC8+xQ/TYsJoufB4loQOgRWg3P
IW11em3DagI5bZb44VuCloQxg9qgkdq6HXOTDkgUFVHKIUDDfZy97Vc6hKRMNawK
LuwCSychmxMfljRwEkR/DQWFdbx+xaKU24loMF0UOb9df7lZ068=
=ihbl
-----END PGP SIGNATURE-----

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-utopia-maintainers/attachments/20260928/fc5994da/attachment.sig>


More information about the Pkg-utopia-maintainers mailing list