#1136299 yelp: security vulnerability fixed in 49.1

Package:
src:yelp
Source:
src:yelp
Submitter:
Jeremy Bícha
Date:
2026-05-19 20:13:01 UTC
Severity:
normal
Tags:
#1136299#5
Date:
2026-05-11 17:36:16 UTC
From:
To:
Sandbox escape hardening was done in yelp's recent 49.1 release that
was discussed more today at

https://blogs.gnome.org/mcatanzaro/2026/05/11/flatpak-sandbox-escape-via-yelp/

A CVE has been requested, but we don't need to wait for it to be
assigned to fix this issue.

The issue is fixed with these 2 upstream commits:
https://gitlab.gnome.org/GNOME/yelp/-/commit/d220aa2f754eed4e6a006a4acaa68b31892dea2b
https://gitlab.gnome.org/GNOME/yelp/-/commit/c8c8244c8a812860782d635890c9b6c43ecc2639

This issue has already been fixed in unstable.

Thank you,
Jeremy Bícha

#1136299#10
Date:
2026-05-11 17:40:09 UTC
From:
To:

#1136299#17
Date:
2026-05-14 09:02:35 UTC
From:
To:

#1136299#22
Date:
2026-05-14 09:07:58 UTC
From:
To:
 > This issue has already been fixed in unstable.

is there any plan to have a fix for stable-security?

We're releasing Tails 7.8, and we'll freeze on Wednesday morning, so ideally we'd like to have a fix
for that by that date.

#1136299#27
Date:
2026-05-14 11:46:39 UTC
From:
To:
boyska:
 > is there any plan to have a fix for stable-security?

I manually tested that, by cherry-picking commits c8c8244c8a812860782d635890c9b6c43ecc2639
d220aa2f754eed4e6a006a4acaa68b31892dea2b, I can get a package which prevents the PoC[1] from working.

I haven't tested 3c1ad5579b7fdcf0ed0a40fe21ecbdc69a9249e8 or
a2f3caf8500287981331c4ff54369e9c5747cd9d, which also seem very relevant (and are included in 42.3).

Hope this helps,

[1] https://gist.github.com/parrot409/e970b155358d45b298d7024edd9b17f2

#1136299#32
Date:
2026-05-19 13:11:29 UTC
From:
To:
 > I manually tested that, by cherry-picking commits c8c8244c8a812860782d635890c9b6c43ecc2639
 > d220aa2f754eed4e6a006a4acaa68b31892dea2b, I can get a package which prevents the PoC[1] from working.
 > [1] https://gist.github.com/parrot409/e970b155358d45b298d7024edd9b17f2

ooops, that wasn't the right PoC to test. We couldn't reproduce the PoC on Trixie, see
https://gitlab.tails.boum.org/tails/tails/-/work_items/21584#note_284203

#1136299#37
Date:
2026-05-19 20:11:02 UTC
From:
To:
Sorry, I don't have the spare capacity to land a stable security fix
in the next few days.

Thank you,
Jeremy Bícha