- Package:
- src:flatpak
- Source:
- src:flatpak
- Submitter:
- Simon McVittie
- Date:
- 2026-10-02 15:19:04 UTC
- Severity:
- normal
- Tags:
Flatpak 1.18.4 addresses multiple security vulnerabilities:
I intend to fix these as a batch, in both testing/unstable and stable,
so reporting one bug for the whole batch.
smcv
We believe that the bug you reported is fixed in the latest version of
flatpak, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1149218@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated flatpak package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 28 Sep 2026 14:10:44 +0100
Source: flatpak
Architecture: source
Version: 1.18.4-1
Distribution: unstable
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1149218
Changes:
flatpak (1.18.4-1) unstable; urgency=high
.
* New upstream security fix release (Closes: #1149218)
- Fix two related symlink traversal vulnerabilities to prevent arbitrary
file deletion and limited file overwriting outside the deploy
directory, and harden related code paths against symlink traversal
(deletion: CVE-2026-97023, GHSA-5p67-xh8x-rq54)
(overwriting: CVE-2026-97024, GHSA-8xgq-v545-vgvf)
- Don't write authentication token to disk when using OCI remotes
(CVE-2026-97025, GHSA-7rvf-rqr3-43j4)
- Restrict permissions of temporary directories /var/tmp/flatpak-cache-*
(CVE-2026-97026, GHSA-r9w3-qx54-qvc8)
- Filter D-Bus .service files and freedesktop.org .desktop files
with an allowlist to prevent denial of service and possibly
sandbox escape
(CVE-2026-97027, GHSA-v64f-hrwr-j4vh)
- Prevent sandboxed processes from killing a parent process outside the
sandbox
(CVE-2026-97029, GHSA-f3p8-vr7v-gxf2)
Checksums-Sha1:
967772d60a4df907b967ed12d82221a70a957836 4054 flatpak_1.18.4-1.dsc
645233c14269778626bb877ea0816c7e34f01326 1363232 flatpak_1.18.4.orig.tar.xz
096aa4bf12b1a0cfd8e9146768cc7c06ff5815a3 44348 flatpak_1.18.4-1.debian.tar.xz
633323fae0dcaec032c9639c582bf012c00a7f76 4471020 flatpak_1.18.4-1.git.tar.xz
5246a7780895cf5d960d147997b791ad55376a5f 17728 flatpak_1.18.4-1_source.buildinfo
Checksums-Sha256:
06a57f749603be0c70aea4e096c8370f4dc20a6c8c1f0c140d1b7d2d2e9982d2 4054 flatpak_1.18.4-1.dsc
b899a7a00c48d2c626cb8ec33fe556720b376c25805d7222430c0fdca4c6ac8d 1363232 flatpak_1.18.4.orig.tar.xz
9c9ff4be6c5e038b3829ace710baa0480452f299504d7b1c9ea653f96ee354b9 44348 flatpak_1.18.4-1.debian.tar.xz
6b7ccbd0a3c874d825ae9280bd03255bd7ed459b04d16d57358de334ecc92151 4471020 flatpak_1.18.4-1.git.tar.xz
b56a313cd736a826be6d07f3dab488d94394bc242c22a105759a8de364f320ca 17728 flatpak_1.18.4-1_source.buildinfo
Files:
f3a7aeb93563e902bbb86d987dcfbdc1 4054 admin optional flatpak_1.18.4-1.dsc
70b21dc1d5e7672fd7b64bc645d74fbc 1363232 admin optional flatpak_1.18.4.orig.tar.xz
a0c78c02ee3e109725a9ddf0a686068d 44348 admin optional flatpak_1.18.4-1.debian.tar.xz
cbd5284db4f1ab9cdddaba3df3290476 4471020 admin None flatpak_1.18.4-1.git.tar.xz
263f8468de4b8bb768d759caedfaba1e 17728 admin optional flatpak_1.18.4-1_source.buildinfo
Git-Tag-Info: tag=83af0460a22a7c14fbb9a8753adf61346f5c2f81 fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <smcv@debian.org>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmq6Z/MACgkQYG0ITkaD
wHnfaBAA6MKbi916G052dA351W0pNDvezTaT5ev6dzFpgYEDIBImFPXJ+vdBpdAt
I4aqLR6L1oWgPyaYiWtXEyOxWfXAslsRSYJ5lKogwC4Ei890hEyekDPSAp7rdcsn
EbYPNS1utjLYNnnU8NTwkfQ4VAhTABoJbXMerUHFOEDPC1EXBtrbFbPrSoxz2AjE
2hKwSpcPUsV3IEKEI/oRP7jqBTaV2ujIkeCVVxDOO6tDZ3V50IYgCtXvCeMoxmf/
Ubfw9l5mnOksm8HZTniE5NG7Mm0OIzzpow7Hghe+9Ggcd1OPv3cM9KVAPlqp8iUk
CLJtCSJV9iDuH+3+9EYYXI8/CZgdVNFJOdlzdLeRwU1gTPY/YFwLy5KtXjbUC366
PtkyVTiOq5x5gbVxtKx3JkXtL9pDgWyDzzc2t9Tce5GPBFuYc//HhXRje6BPJv6s
6Bkusd4lbxVroeJuU3SGeqeaz4W9YGrIoxkChxU+iS7tjvokC7uzqZLsOkG0HUws
HajmhK8d3pVU+SaksCQmgVtmkJwoulf0d4xUNnYAKp6MalduhPs8ihHo+RleDP04
xWcnFZZBBRPXz8Sux4fKiHVoLt6qw9gQ1DSCWgkwF8s9KkjOB7xrUCjDTaMx/t6M
Sm589KojvUUMJjrAJQDVUbQ4d8uit6X8SZBjCtNWMmZ8yOwSLHg=
=lUkg
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
flatpak, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1149218@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated flatpak package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 28 Sep 2026 14:13:01 +0100
Source: flatpak
Architecture: source
Version: 1.16.6-1~deb13u3
Distribution: trixie-security
Urgency: high
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1149218
Changes:
flatpak (1.16.6-1~deb13u3) trixie-security; urgency=high
.
* d/patches: Backport security fixes from 1.18.4 (Closes: #1149218):
- Fix two related symlink traversal vulnerabilities to prevent arbitrary
file deletion and limited file overwriting outside the deploy
directory, and harden related code paths against symlink traversal
(deletion: CVE-2026-97023, GHSA-5p67-xh8x-rq54)
(overwriting: CVE-2026-97024, GHSA-8xgq-v545-vgvf)
- When using OCI remotes, don't make authentication token readable by
other users
(CVE-2026-97025, GHSA-7rvf-rqr3-43j4)
- Restrict permissions of temporary directories /var/tmp/flatpak-cache-*
(CVE-2026-97026, GHSA-r9w3-qx54-qvc8)
- Filter D-Bus .service files and freedesktop.org .desktop files
with an allowlist to prevent denial of service and possibly
sandbox escape
(CVE-2026-97027, GHSA-v64f-hrwr-j4vh)
- Prevent sandboxed processes from killing a parent process outside the
sandbox
(CVE-2026-97029, GHSA-f3p8-vr7v-gxf2)
* Mention CVE-2026-90616, CVE-2026-92162 in previous changelog entry
Checksums-Sha1:
f72674b664b1c7c111c6648d098e11952982f536 3741 flatpak_1.16.6-1~deb13u3.dsc
b6d693e6c8de02f7fa16821645c8bc38172dfbc3 86412 flatpak_1.16.6-1~deb13u3.debian.tar.xz
e88ee46b27a06247220e7ef2f7214ea04a12105f 15479 flatpak_1.16.6-1~deb13u3_source.buildinfo
Checksums-Sha256:
5f4bb9d94e039f6c0c35c28b22b2d0f6030b6d83560d8c80996c399a7a43b142 3741 flatpak_1.16.6-1~deb13u3.dsc
21cf5dbf20f453f007476322f864552b45a0f8521d86b907c7a015fba82141ac 86412 flatpak_1.16.6-1~deb13u3.debian.tar.xz
a7a6bb191854b17889c755b5f30bf83116897f76f114ca9f8e7e259933a3ec82 15479 flatpak_1.16.6-1~deb13u3_source.buildinfo
Files:
f03cade7037f07cc784b8a261c6cc7d0 3741 admin optional flatpak_1.16.6-1~deb13u3.dsc
10f95f8be7b5fef7889275e0fd2c0ec2 86412 admin optional flatpak_1.16.6-1~deb13u3.debian.tar.xz
5be08845ca189203fc6f123b924513e9 15479 admin optional flatpak_1.16.6-1~deb13u3_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmq6bjgACgkQI1wJnT6z
MHYH6Q//bnRqvZaYgiWNVLUeK8WN8L8K2IJXRsUfhEwUhNQP+mB8AL6buz9s0Mfy
rJfrGsKvgq61Z6S0JMs9zNUPHVvqh+fT4mjJ+Z+8r9jLjjumsIQqdhHFlDSVGKzQ
0hc2K665Zc5Y+eIHHx3K0zrNzfiwCrnTkxvDRB110NGQdspcDGKf1koBN7fXCJb3
znEQDwNFwTDYd7QqfNl1lNs327cPZnS6MDsxJFCBWplS/kLvbiGAZ8RdJH5IyYkq
xtdRgsxT/xkKu+WnnLXvbyeBaxWAyPPXYYhf/kcYgHDEU2GHy1BfD7o1+0ueBJVf
VWLltG+2jy/OHFcKm8d6Xky2rT6PBiInpwxscJTk0K/23nxEXGEpwmtFVHxDgcP9
1/dkBUIiyCfSUj5lxiRAXVaYhCFyoPi6K3IW5iy6Tzj9Y21N0IqAtmeqwc6y8WVh
GnCQT1C/J25FisFGFYdgPP0k73Krj7/zCRA72iU1w2nksx+SerRnDOgeXswpL2+L
jqzwjm/ki/5wfkVONaobCC63F8tCybmcOqZ8Q7RC8+xQ/TYsJoufB4loQOgRWg3P
IW11em3DagI5bZb44VuCloQxg9qgkdq6HXOTDkgUFVHKIUDDfZy97Vc6hKRMNawK
LuwCSychmxMfljRwEkR/DQWFdbx+xaKU24loMF0UOb9df7lZ068=
=ihbl
-----END PGP SIGNATURE-----