-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Aug 2026 14:03:38 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: amd64 Version: 1.16.6-1~deb13u2 Distribution: trixie-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Closes: 1144130 Changes: flatpak (1.16.6-1~deb13u2) trixie-security; urgency=high . * d/patches: Backport security fixes from 1.18.1 (Closes: #1144130) - d/p/libglnx/*.patch: Backport glnx_chase_and_mkdirat() utility function, required by some of the security fixes below - d/p/tests/*.patch: Backport unit tests fixes which are required by the tests for some of the security fixes below - d/p/GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/*.patch: + GHSA-fqx6-vh4p-42cg: Fix writing outside installation directory via crafted commit metadata. A malicious or compromised Flatpak repository could write attacker-controlled files outside /var/lib/flatpak as root. + GHSA-8qxj-x646-phcm: Fix writing outside working directory in `flatpak build-init`. A malicious or compromised SDK could write outside the intended working directory when a developer starts using it for a build. - d/p/GHSA-qrwq-7qwx-q9rp/*.patch: Fix local privilege escalation involving revokefs. A malicious local user could write files outside /var/lib/flatpak as root by tampering with OSTree objects after signature verification. - d/p/GHSA-8688-9x26-hhxj/*.patch: Fix a sandbox escape involving directories inside ~/.var/app/APP_ID. A malicious or compromised Flatpak app could write to arbitrary files outside its sandbox. - d/p/GHSA-99wv-m8rp-g58x/*.patch: Fix a sandbox escape involving the ld.so cache. A malicious or compromised Flatpak app could write files with a fixed name and limited control over content outside the sandbox. - d/p/GHSA-v2gw-v9h5-9q4x/*.patch: Fix local privilege escalation involving crafted OCI architecture names. A malicious local user on a system with an OCI remote configured (unusual on non-Fedora systems) could trick the flatpak-system-helper process into writing outside /var/lib/flatpak. - d/p/GHSA-w69g-9x8j-7p8f/*.patch: Fix reading outside sandbox involving crafted extension metadata. A malicious or compromised Flatpak app could find out whether specific files exist outside the sandbox. - d/p/GHSA-q4gr-vc25-57m5/*.patch: Fix anti-downgrade checks for components installed system-wide. A malicious local user with an active local login session could downgrade an app, runtime or extension to an older, known-vulnerable version and use this to attack other local users. - d/p/GHSA-jr92-2v97-wgvc/*.patch: Fix a buffer overflow when installing or updating from a malicious OCI registry, not believed to be practically exploitable on 64-bit systems. - d/p/hardening/*.patch: Harden file accesses against path traversal, fixing issues that were initially thought to be security vulnerabilities similar to those above, but on further analysis do not seem to be exploitable. - d/p/GHSA-r7hp-698j-2h6c/*.patch: Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts so that GTK accessibility features work as intended. Previously, these accessibility features only worked accidentally as a result of an xdg-dbus-proxy security issue, fixed in 0.1.8. * d/patches: Add additional bug fixes from upstream 1.16.x branch - d/p/subprojects-Ignore-.wraplock-file-generated-by-recent-Mes.patch, d/p/bwrap-Clarify-a-comment.patch, d/p/subprojects-Update-dbus-proxy.wrap-to-v0.1.7.patch: Resync with upstream source, no functional changes - d/p/dir-Use-flatpak_bwrap_child_setup_inherit_fds_cb-to-apply.patch: Silence a spurious warning when apps use the extra_data mechanism - d/p/portal-Actually-use-the-AppInfo-hash-table.patch: Fix a memory leak and potential rare crashes in flatpak-portal Checksums-Sha1: 9ac9c96f583d0fb692c783255b12baea84d9c843 7701224 flatpak-dbgsym_1.16.6-1~deb13u2_amd64.deb 793af7937c7d6c41abb4a86996bce7ce31232fe2 10991808 flatpak-tests-dbgsym_1.16.6-1~deb13u2_amd64.deb 6bcf80984e87d2291992d8db9d6c3f156e625ad2 1453028 flatpak-tests_1.16.6-1~deb13u2_amd64.deb ad87360220d649f0bfeb5d2b89af6e7838df787e 17631 flatpak_1.16.6-1~deb13u2_amd64-buildd.buildinfo f648a0c941427cb93080dd684d2fdfbc59aa9ed2 1551900 flatpak_1.16.6-1~deb13u2_amd64.deb d8b934f38868fe9ec36e26a42187e7367eadbfd2 29332 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_amd64.deb e989b55aded530d4fc78d1e2e5d8e8b7b227fec5 73624 libflatpak-dev_1.16.6-1~deb13u2_amd64.deb 36bad49e4bb3ed42b27e81843d19d62ac5f10c14 1764328 libflatpak0-dbgsym_1.16.6-1~deb13u2_amd64.deb c30692d1e64e5f5d36f14cca4349c17b785467a3 394844 libflatpak0_1.16.6-1~deb13u2_amd64.deb Checksums-Sha256: 4dc667f80466feb2301f2ad9feee6065bc2272273622abd49a93105a93f52862 7701224 flatpak-dbgsym_1.16.6-1~deb13u2_amd64.deb cdb215d784ce6a64e74d99b65975b39a628f49866123e5c7628cffbbc3683824 10991808 flatpak-tests-dbgsym_1.16.6-1~deb13u2_amd64.deb a1e1de33ed2ce5f7b9ec7d329492a4160bb16af10116b5b740eda3b159e26755 1453028 flatpak-tests_1.16.6-1~deb13u2_amd64.deb a8ddee951327fb9ebd8e2ecc8f82585006eefd9d258bc7800ef3f9eba05736c8 17631 flatpak_1.16.6-1~deb13u2_amd64-buildd.buildinfo 394685e73bb5c9ca59cdf630353f21f88290b4b3b26731a7dd1f2be5a2f87d0a 1551900 flatpak_1.16.6-1~deb13u2_amd64.deb 402f9f1631948eddb75deedccd2590b3b0bd68b8c77816ca5fbaadae4d8787ac 29332 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_amd64.deb 09d460c8f634348fc59263bf55feab571ff7ffa68376a6f5a480444f6811f395 73624 libflatpak-dev_1.16.6-1~deb13u2_amd64.deb 7fee62609f34682804c9a69386953e8e02cb671c9f946bcdfecf5387316a1ce3 1764328 libflatpak0-dbgsym_1.16.6-1~deb13u2_amd64.deb 17dbffd5c5094434c2f423ddae8397a8b86e051003a06e5b8e85bf47d2c8ad03 394844 libflatpak0_1.16.6-1~deb13u2_amd64.deb Files: b5947743e12f75fce7d45a2d8720413c 7701224 debug optional flatpak-dbgsym_1.16.6-1~deb13u2_amd64.deb 3639101032f9cf491cea95492160b0a9 10991808 debug optional flatpak-tests-dbgsym_1.16.6-1~deb13u2_amd64.deb a6643c87c337425efc150245449f60b1 1453028 misc optional flatpak-tests_1.16.6-1~deb13u2_amd64.deb e541343e4965a7f9202d852cc57b2ba5 17631 admin optional flatpak_1.16.6-1~deb13u2_amd64-buildd.buildinfo 327e0f5663eb01844cae906b9ccc30e6 1551900 admin optional flatpak_1.16.6-1~deb13u2_amd64.deb 406afc733b83362f54435da9ff6ee16c 29332 introspection optional gir1.2-flatpak-1.0_1.16.6-1~deb13u2_amd64.deb 9c21953d4d1c84c43c9f39e19df72855 73624 libdevel optional libflatpak-dev_1.16.6-1~deb13u2_amd64.deb 84e4e4afcc39cc1a7a9a6a4066b798df 1764328 debug optional libflatpak0-dbgsym_1.16.6-1~deb13u2_amd64.deb bb08e5508f692b60bba6d26edce4ac66 394844 libs optional libflatpak0_1.16.6-1~deb13u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7cQ9mRD4+dWjjrb6PkCWRKsh20cFAmp7PbIACgkQPkCWRKsh 20f6+hAAsZ4DmczZ4mUgZ0DvZ8eZl6C4Kj7TWGfNIOxpwz7SIa6VFH+KNi0KBqEu 6NdPgeS8akTwxjo9TdTfJeVaod8M5Nr56WRKBSgN9dRXVU3UKF6wHNmpEils25u+ Vvtv6IA0G7UBJ1vudCWD4P8wkjIrFYowa7T1tjIXgXuQNBskeYN97BSPW1Vzws5r 9cLAD57dMNrxoA+SXkDMfbev2cby+VWS9SXo0kLltruPZbXXJHWkwYgNAz89coNY w+K6jGXkXKHqXVEPf+qDuhBzNeyygOEcBmpMWwzcYwN5INhgMBTcBnqt/yym4Hus I5Wap1ApfW/gtfn4aPeVFReICjfyEhbEqC+hj60Z84qAQk/t9YAf4ymo0M7iOq0X 1NxDIw7ULznG7bIAVGBIv2zJoy0XJ5bswWL9KV/hss0V08oRERq6UqSoqxtL0Pbo nFKK1DA3bS1/6EoTE6AWPDsxEUV/dQYZlTfF1iQ8pEJyW7o7XcW+g+yCOwYqOE37 9mYP2EcoVvZgzKgxJMdkTE/JdY+RbDMLc2MVOgUE/9JW5ILjsF2Yii8qXpz/wVrr VOT2VQtC8Tsg2tBNH8KiWadPWnMGfKwlSPoEdINwgEdXCt5Klq18Q8B052U9o8v3 QYj1Y07cK2FNVr4wPGICpnYsdbFEnlZp2EcygEzdbhvksnWfuS4= =OSi/ -----END PGP SIGNATURE-----