- Package:
- src:flatpak
- Source:
- src:flatpak
- Submitter:
- Simon McVittie
- Date:
- 2026-08-21 13:49:02 UTC
- Severity:
- normal
- Tags:
This bug report is a placeholder for all of the vulnerabilities that are
fixed in prerelease 1.19.0. The same vulnerabilities will also be fixed
in a 1.18.1 stable release, soon. More details when they are available.
smcv
vulnerabilities. We don't have CVE IDs for any of them yet, so they're referenced by GHSA- IDs. The most serious are a full sandbox escape (GHSA-8688-9x26-hhxj) and local root privilege escalation (GHSA-qrwq-7qwx-q9rp, GHSA-fqx6-vh4p-42cg). I will upload 1.18.1 to unstable soon: automated tests are still running, but manual testing was successful. All of the vulnerabilities except for GHSA-9rww-v4mm-x4jg affect trixie as well. GHSA-9rww-v4mm-x4jg is a problem with a new feature that was added in the 1.17.x/1.18.x cycle, so trixie is not vulnerable to it. https://people.debian.org/~smcv/bug1144130/trixie/ contains backported fixes for trixie, covering everything except GHSA-9rww-v4mm-x4jg. As discussed by private email with the security team, this also includes pending upstream non-security bug fixes from the flatpak-1.16.x branch. May I upload? For convenience, https://people.debian.org/~smcv/bug1144130/trixie/rc/ contains source and amd64 binaries for a functionally equivalent test-build (the only difference is the changelog). Thanks, smcv
Hello, Bug #1144130 in flatpak reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/debian/flatpak/-/commit/6805d2213c5263396921df21463f284bb581544a ------------------------------------------------------------------------ New upstream security fix release Closes: #1144130 ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1144130
We believe that the bug you reported is fixed in the latest version of
flatpak, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144130@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated flatpak package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 11 Aug 2026 14:02:52 +0100
Source: flatpak
Architecture: source
Version: 1.18.1-1
Distribution: unstable
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1144130
Changes:
flatpak (1.18.1-1) unstable; urgency=high
.
* New upstream security fix release (Closes: #1144130)
- GHSA-fqx6-vh4p-42cg:
Fix writing outside installation directory via crafted commit metadata.
A malicious or compromised Flatpak repository could write
attacker-controlled files outside /var/lib/flatpak as root.
- GHSA-qrwq-7qwx-q9rp:
Fix local privilege escalation involving revokefs.
A malicious local user could write files outside /var/lib/flatpak
as root by tampering with OSTree objects after signature verification.
- GHSA-8688-9x26-hhxj:
Fix a sandbox escape involving directories inside ~/.var/app/APP_ID.
A malicious or compromised Flatpak app could write to arbitrary files
outside its sandbox.
- GHSA-99wv-m8rp-g58x:
Fix a sandbox escape involving the ld.so cache.
A malicious or compromised Flatpak app could write files with a fixed
name and limited control over content outside the sandbox.
- GHSA-v2gw-v9h5-9q4x:
Fix local privilege escalation involving crafted OCI architecture names.
A malicious local user on a system with an OCI remote configured
(unusual on non-Fedora systems) could trick the flatpak-system-helper
process into writing outside /var/lib/flatpak.
- GHSA-w69g-9x8j-7p8f:
Fix reading outside sandbox involving crafted extension metadata.
A malicious or compromised Flatpak app could find out whether specific
files exist outside the sandbox.
- GHSA-q4gr-vc25-57m5:
Fix anti-downgrade checks for components installed system-wide.
A malicious local user with an active local login session could
downgrade an app, runtime or extension to an older, known-vulnerable
version and use this to attack other local users.
- GHSA-8qxj-x646-phcm:
Fix writing outside working directory in `flatpak build-init`.
A malicious or compromised SDK could write outside the intended
working directory when a developer starts using it for a build.
- GHSA-jr92-2v97-wgvc:
Fix a buffer overflow when installing or updating from a malicious OCI
registry, not believed to be practically exploitable on 64-bit systems.
- GHSA-r7hp-698j-2h6c:
Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts
so that GTK accessibility features work as intended.
Previously, these accessibility features only worked accidentally as a
result of an xdg-dbus-proxy security issue, fixed in 0.1.8.
- Numerous non-security-related bug fixes
Checksums-Sha1:
1c03d09f22fdec31cb75c907e1daf7a952bd6790 4057 flatpak_1.18.1-1.dsc
f2378fd645e7fcf41e8f67849fadaecec613c22a 1355712 flatpak_1.18.1.orig.tar.xz
7fe64816a3b19373b6d6f6203a4e62e7f01cc04d 43804 flatpak_1.18.1-1.debian.tar.xz
61da1b8d64264fda5ff3f1c40db05129e8dea988 4650296 flatpak_1.18.1-1.git.tar.xz
79cabf2eca03415941e8eabaa0ab245232206862 17556 flatpak_1.18.1-1_source.buildinfo
Checksums-Sha256:
84b0a6ec350cd934f60e5c21b0d0727a9d90e209fe59e7f2cbf7ced32fde93fc 4057 flatpak_1.18.1-1.dsc
bc683fc916ed21c0524bb064f358c2ac18586b8ec88c76f2f7f289877521631c 1355712 flatpak_1.18.1.orig.tar.xz
e863fbe3457dc2568b4ca5de3eef841c7e98813b98b3aa2476844224edf19454 43804 flatpak_1.18.1-1.debian.tar.xz
dbc43065ffcea6da750db2fb8e1623ed97efce280edf2db21f1e6122f4c12b82 4650296 flatpak_1.18.1-1.git.tar.xz
3297b278511c08405e158be5ca2ca786f0ed08310a5fef31afae5fd89a0f2440 17556 flatpak_1.18.1-1_source.buildinfo
Files:
776f43644f37db94e2837fc21ab56c5d 4057 admin optional flatpak_1.18.1-1.dsc
f20f8b81b9bc979db057a9c2e717cf14 1355712 admin optional flatpak_1.18.1.orig.tar.xz
e9d937a99d198ced639b6be170bfb6f9 43804 admin optional flatpak_1.18.1-1.debian.tar.xz
b208d76105c10118cb33bc0d3f5d3b03 4650296 admin None flatpak_1.18.1-1.git.tar.xz
c8906ee405d6a801b53f306b54832d4a 17556 admin optional flatpak_1.18.1-1_source.buildinfo
Git-Tag-Info: tag=f6dbe0ad231a7a761f823ef3c062a237a02cab7f fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <smcv@debian.org>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmp7K0wACgkQYG0ITkaD
wHnfeQ//YweEOLWaN7D+pFQf/4AfSCvSgGF//of7pv1dZbFHLWs1FW4hYlXZ814t
Br4TW4xLRWCrLCezYq1sWMf9Sp0JQgK+mrP/0YlRos6IaV0P4NTzyCyd6+kcx06s
ieIWMVew99fvKt/kvmVUIwAv3idekq2dx/UBUlJMJEVDcSVfPKEJYWEt2tIsNt+V
rt2owh/kxiy1Rulj3ozTjUMk4qnssmn+K33vGdwF4Y1sKeByCiZbD/TQgzlUBkp5
+nIwj+Cr7Rk/bxhmSAC2bCw0YeuhWizQXyEsM3/0I7CiYosGF43j576F7PXVAABQ
988W6U9AKHC9aPvXbASHrrJKgLRz3rIfxs9M9jsYiACfgwvmUZ276UrY1968/e/d
TSIwNlwW6ISJfRrhQCzcWoqlzxyO19QsQ3N9TFU/X0DLSEF/lpg5DS/C7NgxnyWI
SZrMqcTaRteSWKtAHBC5+EI2kNyBqgwDX7UGrGksqmpQAMpdPhoV2ll2p7wOF647
C5DB8DqRfPkvmI7kmeg+/hp4z7Au8K7P4dcQEDxB7DX2y8T1JU09lb+kWq8AQFZU
dCBGlS0bzGg96naxsER1zwIazMp2cMthIjr2hI/luO/5CBnZJ675NkLERQmzWhs0
gWNumUiBo7Tzy8uXybyTG6Ag+gyAdns/t9xjW+J4A5KWamPkCTo=
=BU4P
-----END PGP SIGNATURE-----
Hi Simon, Yes please do upload to security-master (just confirming, you should already have an ack from Moritz on the flatpak update). Regards, Salvatore
Thanks, uploaded.
Thanks, builds are trickling in, I'll do a some more tests
with the flatpaks I personally use and then the DSAs for flatpak
and xdg-dbus-proxy will go out tomorrow.
Cheers,
Moritz
The DSA has been released (along with xdg-dbus-proxy), thanks!
We'll backfill the CVE IDs in the Security Tracker when they are available.
Cheers,
Moritz
We believe that the bug you reported is fixed in the latest version of
flatpak, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144130@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated flatpak package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 11 Aug 2026 14:03:38 +0100
Source: flatpak
Architecture: source
Version: 1.16.6-1~deb13u2
Distribution: trixie-security
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1144130
Changes:
flatpak (1.16.6-1~deb13u2) trixie-security; urgency=high
.
* d/patches: Backport security fixes from 1.18.1 (Closes: #1144130)
- d/p/libglnx/*.patch:
Backport glnx_chase_and_mkdirat() utility function, required by some
of the security fixes below
- d/p/tests/*.patch:
Backport unit tests fixes which are required by the tests for some
of the security fixes below
- d/p/GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/*.patch:
+ GHSA-fqx6-vh4p-42cg:
Fix writing outside installation directory via crafted commit metadata.
A malicious or compromised Flatpak repository could write
attacker-controlled files outside /var/lib/flatpak as root.
+ GHSA-8qxj-x646-phcm:
Fix writing outside working directory in `flatpak build-init`.
A malicious or compromised SDK could write outside the intended
working directory when a developer starts using it for a build.
- d/p/GHSA-qrwq-7qwx-q9rp/*.patch:
Fix local privilege escalation involving revokefs.
A malicious local user could write files outside /var/lib/flatpak
as root by tampering with OSTree objects after signature verification.
- d/p/GHSA-8688-9x26-hhxj/*.patch:
Fix a sandbox escape involving directories inside ~/.var/app/APP_ID.
A malicious or compromised Flatpak app could write to arbitrary files
outside its sandbox.
- d/p/GHSA-99wv-m8rp-g58x/*.patch:
Fix a sandbox escape involving the ld.so cache.
A malicious or compromised Flatpak app could write files with a fixed
name and limited control over content outside the sandbox.
- d/p/GHSA-v2gw-v9h5-9q4x/*.patch:
Fix local privilege escalation involving crafted OCI architecture names.
A malicious local user on a system with an OCI remote configured
(unusual on non-Fedora systems) could trick the flatpak-system-helper
process into writing outside /var/lib/flatpak.
- d/p/GHSA-w69g-9x8j-7p8f/*.patch:
Fix reading outside sandbox involving crafted extension metadata.
A malicious or compromised Flatpak app could find out whether specific
files exist outside the sandbox.
- d/p/GHSA-q4gr-vc25-57m5/*.patch:
Fix anti-downgrade checks for components installed system-wide.
A malicious local user with an active local login session could
downgrade an app, runtime or extension to an older, known-vulnerable
version and use this to attack other local users.
- d/p/GHSA-jr92-2v97-wgvc/*.patch:
Fix a buffer overflow when installing or updating from a malicious OCI
registry, not believed to be practically exploitable on 64-bit systems.
- d/p/hardening/*.patch:
Harden file accesses against path traversal, fixing issues that
were initially thought to be security vulnerabilities similar to
those above, but on further analysis do not seem to be exploitable.
- d/p/GHSA-r7hp-698j-2h6c/*.patch:
Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts
so that GTK accessibility features work as intended.
Previously, these accessibility features only worked accidentally as a
result of an xdg-dbus-proxy security issue, fixed in 0.1.8.
* d/patches: Add additional bug fixes from upstream 1.16.x branch
- d/p/subprojects-Ignore-.wraplock-file-generated-by-recent-Mes.patch,
d/p/bwrap-Clarify-a-comment.patch,
d/p/subprojects-Update-dbus-proxy.wrap-to-v0.1.7.patch:
Resync with upstream source, no functional changes
- d/p/dir-Use-flatpak_bwrap_child_setup_inherit_fds_cb-to-apply.patch:
Silence a spurious warning when apps use the extra_data mechanism
- d/p/portal-Actually-use-the-AppInfo-hash-table.patch:
Fix a memory leak and potential rare crashes in flatpak-portal
Checksums-Sha1:
23819bb80df3336957c6a48b2d9e8b8cb2d47237 3741 flatpak_1.16.6-1~deb13u2.dsc
ba597a6fe31a0749cb3f8835b72885e5b235b9d2 76448 flatpak_1.16.6-1~deb13u2.debian.tar.xz
131e098bbf4d64f1f69a4ceb55f12949f12b4b87 15293 flatpak_1.16.6-1~deb13u2_source.buildinfo
Checksums-Sha256:
5aa8c6319336226ac6638acd8df94b63bc27da4621a478f3e47e0f9f564c18de 3741 flatpak_1.16.6-1~deb13u2.dsc
bac37dc8430afe688734263f7efecb8a9bfff6098011d24a1647b2f09c99d790 76448 flatpak_1.16.6-1~deb13u2.debian.tar.xz
cd3a79eddc583a2c65b61a71f05b936bef12a05362d5caa2233b3e1ed7bf00f6 15293 flatpak_1.16.6-1~deb13u2_source.buildinfo
Files:
4ca674bfa72b7210851606ff843ed90e 3741 admin optional flatpak_1.16.6-1~deb13u2.dsc
51eeccf1f9d601f93a4a2ca595a714fe 76448 admin optional flatpak_1.16.6-1~deb13u2.debian.tar.xz
c295c3e06eaf5d5e5a86cfe665b6a27c 15293 admin optional flatpak_1.16.6-1~deb13u2_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmp7OMQACgkQI1wJnT6z
MHbM7BAAyWAr40Kt7lpDvCJmkCS1LcRTBexSBmchq8rrP0yeLQwoJ3KynC0lI7FO
ZhwhmnqCeBu+s0X5dH409FYGV8SimHLWw7ihPnnqZUvc0bjEGidanULENxnb3r2G
v5r6RrI93xUZDVkR3ZyrHBUV4i4WSZJD9dMKf91UWuFh2InPz2edIhi86nRkZSox
r4VDn6/AArAJ5yfBOeV001AUOGwFVvCmzZzYmys1Bl0aTtHDeJrZu7aE3JIsf1li
AeHxN7sul1Ti3hqtlglL7ISVsdNycgqqU8T4osTDDfOU5Xk2yGk97yePRuZ1Du4I
p5h+3IWAQMoOsZy3eYnKALiObqtGmW8iZw4SYLdNOtPLmmlynvbcfffoEe6r9JCz
3ONRXTmu6KpwQFXVPx0oAN9z0sz8ynA8SeXxg4Q0YfsVA/+cT6PdAfzNezvFbEM8
yYn4MOgi3iI5XPx9UG2ecitUZAPjRbG3py7ey9k3qVuP7XcvI28umZ0opPPjHCZ9
AHZmIQHz9WYHsJSGxI8cvXgNYDp4SCSk3KWfj0Go+q/wvRW00FYW+2AiKELuNauN
vY/cgKw4/xorvUYTzBRoy3e2YD0QHbAYgW6Z9UbxKgyp1gpeW9nxim8nNYFlPooK
EVVffgpmXh8hX/FvX57s5/tZ7qzeVHN/uu4hqv4QdorQgW/rVRs=
=d3BX
-----END PGP SIGNATURE-----