Bug#1144130: flatpak: multiple vulnerabilities fixed by 1.18.1

Simon McVittie <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <ansosV1-OUSL2wj1__4315.72128306783$1786456396$gmane$org@definition.pseudorandom.co.uk>
On Tue, 11 Aug 2026 at 13:32:05 +0100, Simon McVittie wrote:
>This bug report is a placeholder for all of the vulnerabilities that are
>fixed in prerelease 1.19.0. The same vulnerabilities will also be fixed
>in a 1.18.1 stable release, soon. More details when they are available.

https://github.com/flatpak/flatpak/releases/tag/1.18.1 lists all the 
vulnerabilities. We don't have CVE IDs for any of them yet, so they're 
referenced by GHSA- IDs.

The most serious are a full sandbox escape (GHSA-8688-9x26-hhxj) and 
local root privilege escalation (GHSA-qrwq-7qwx-q9rp, GHSA-fqx6-vh4p-42cg).

I will upload 1.18.1 to unstable soon: automated tests are still 
running, but manual testing was successful.

All of the vulnerabilities except for GHSA-9rww-v4mm-x4jg affect trixie 
as well. GHSA-9rww-v4mm-x4jg is a problem with a new feature that was 
added in the 1.17.x/1.18.x cycle, so trixie is not vulnerable to it.

https://people.debian.org/~smcv/bug1144130/trixie/ contains backported 
fixes for trixie, covering everything except GHSA-9rww-v4mm-x4jg. As 
discussed by private email with the security team, this also includes 
pending upstream non-security bug fixes from the flatpak-1.16.x branch. 
May I upload?

For convenience, https://people.debian.org/~smcv/bug1144130/trixie/rc/ 
contains source and amd64 binaries for a functionally equivalent 
test-build (the only difference is the changelog).

Thanks,
     smcv
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.