Bug#1144130: flatpak: multiple vulnerabilities fixed by 1.18.1

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <ans0vKhP1RctZOV4__37922.9818166763$1786459396$gmane$org@eldamar.lan>
Hi Simon,

On Tue, Aug 11, 2026 at 02:50:41PM +0100, Simon McVittie wrote:
> On Tue, 11 Aug 2026 at 13:32:05 +0100, Simon McVittie wrote:
> > This bug report is a placeholder for all of the vulnerabilities that are
> > fixed in prerelease 1.19.0. The same vulnerabilities will also be fixed
> > in a 1.18.1 stable release, soon. More details when they are available.
> 
> https://github.com/flatpak/flatpak/releases/tag/1.18.1 lists all the
> vulnerabilities. We don't have CVE IDs for any of them yet, so they're
> referenced by GHSA- IDs.
> 
> The most serious are a full sandbox escape (GHSA-8688-9x26-hhxj) and local
> root privilege escalation (GHSA-qrwq-7qwx-q9rp, GHSA-fqx6-vh4p-42cg).
> 
> I will upload 1.18.1 to unstable soon: automated tests are still running,
> but manual testing was successful.
> 
> All of the vulnerabilities except for GHSA-9rww-v4mm-x4jg affect trixie as
> well. GHSA-9rww-v4mm-x4jg is a problem with a new feature that was added in
> the 1.17.x/1.18.x cycle, so trixie is not vulnerable to it.
> 
> https://people.debian.org/~smcv/bug1144130/trixie/ contains backported fixes
> for trixie, covering everything except GHSA-9rww-v4mm-x4jg. As discussed by
> private email with the security team, this also includes pending upstream
> non-security bug fixes from the flatpak-1.16.x branch. May I upload?

Yes please do upload to security-master (just confirming, you should
already have an ack from Moritz on the flatpak update).

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.