-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Aug 2026 14:03:38 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: armel Version: 1.16.6-1~deb13u2 Distribution: trixie-security Urgency: high Maintainer: armel Build Daemon (arm-ubc-04) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Closes: 1144130 Changes: flatpak (1.16.6-1~deb13u2) trixie-security; urgency=high . * d/patches: Backport security fixes from 1.18.1 (Closes: #1144130) - d/p/libglnx/*.patch: Backport glnx_chase_and_mkdirat() utility function, required by some of the security fixes below - d/p/tests/*.patch: Backport unit tests fixes which are required by the tests for some of the security fixes below - d/p/GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/*.patch: + GHSA-fqx6-vh4p-42cg: Fix writing outside installation directory via crafted commit metadata. A malicious or compromised Flatpak repository could write attacker-controlled files outside /var/lib/flatpak as root. + GHSA-8qxj-x646-phcm: Fix writing outside working directory in `flatpak build-init`. A malicious or compromised SDK could write outside the intended working directory when a developer starts using it for a build. - d/p/GHSA-qrwq-7qwx-q9rp/*.patch: Fix local privilege escalation involving revokefs. A malicious local user could write files outside /var/lib/flatpak as root by tampering with OSTree objects after signature verification. - d/p/GHSA-8688-9x26-hhxj/*.patch: Fix a sandbox escape involving directories inside ~/.var/app/APP_ID. A malicious or compromised Flatpak app could write to arbitrary files outside its sandbox. - d/p/GHSA-99wv-m8rp-g58x/*.patch: Fix a sandbox escape involving the ld.so cache. A malicious or compromised Flatpak app could write files with a fixed name and limited control over content outside the sandbox. - d/p/GHSA-v2gw-v9h5-9q4x/*.patch: Fix local privilege escalation involving crafted OCI architecture names. A malicious local user on a system with an OCI remote configured (unusual on non-Fedora systems) could trick the flatpak-system-helper process into writing outside /var/lib/flatpak. - d/p/GHSA-w69g-9x8j-7p8f/*.patch: Fix reading outside sandbox involving crafted extension metadata. A malicious or compromised Flatpak app could find out whether specific files exist outside the sandbox. - d/p/GHSA-q4gr-vc25-57m5/*.patch: Fix anti-downgrade checks for components installed system-wide. A malicious local user with an active local login session could downgrade an app, runtime or extension to an older, known-vulnerable version and use this to attack other local users. - d/p/GHSA-jr92-2v97-wgvc/*.patch: Fix a buffer overflow when installing or updating from a malicious OCI registry, not believed to be practically exploitable on 64-bit systems. - d/p/hardening/*.patch: Harden file accesses against path traversal, fixing issues that were initially thought to be security vulnerabilities similar to those above, but on further analysis do not seem to be exploitable. - d/p/GHSA-r7hp-698j-2h6c/*.patch: Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts so that GTK accessibility features work as intended. Previously, these accessibility features only worked accidentally as a result of an xdg-dbus-proxy security issue, fixed in 0.1.8. * d/patches: Add additional bug fixes from upstream 1.16.x branch - d/p/subprojects-Ignore-.wraplock-file-generated-by-recent-Mes.patch, d/p/bwrap-Clarify-a-comment.patch, d/p/subprojects-Update-dbus-proxy.wrap-to-v0.1.7.patch: Resync with upstream source, no functional changes - d/p/dir-Use-flatpak_bwrap_child_setup_inherit_fds_cb-to-apply.patch: Silence a spurious warning when apps use the extra_data mechanism - d/p/portal-Actually-use-the-AppInfo-hash-table.patch: Fix a memory leak and potential rare crashes in flatpak-portal Checksums-Sha1: a1e0a7bf488b591725871cffe7f73236c7b71d1e 7217124 flatpak-dbgsym_1.16.6-1~deb13u2_armel.deb 33bb7f5ac6965905fd69768fc36032023d0699c6 10280796 flatpak-tests-dbgsym_1.16.6-1~deb13u2_armel.deb 1d46d7c46c6d04ba1e62ee7eae83a4a36534a6ee 1157916 flatpak-tests_1.16.6-1~deb13u2_armel.deb 3948facf72f17f26cbb4c086eaaf582cdba3a441 17483 flatpak_1.16.6-1~deb13u2_armel-buildd.buildinfo 0bbb9bf582a6b2cf1bb0b04d72bb9b6a025b608d 1372392 flatpak_1.16.6-1~deb13u2_armel.deb 1f831ae2f5af0fc2e53271e4c933a441747ad638 29336 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_armel.deb bc5cb594c47a260835cefca2ade6dc005c965eb1 73636 libflatpak-dev_1.16.6-1~deb13u2_armel.deb b2efe6ac2937f497b9137725b8cbf57126bc6ea6 1717128 libflatpak0-dbgsym_1.16.6-1~deb13u2_armel.deb f8d254d4c0af2a8ee52e9a37e176695059c78406 332664 libflatpak0_1.16.6-1~deb13u2_armel.deb Checksums-Sha256: de9ae89cdcdcdeec7e468bc92ca609d4647898d90302b76cbc4cbc427263fd3d 7217124 flatpak-dbgsym_1.16.6-1~deb13u2_armel.deb 3ff7b83435b948927f22a0872df3916574c0431fbb468dad4a5bdef0f8ae3583 10280796 flatpak-tests-dbgsym_1.16.6-1~deb13u2_armel.deb fff146df6176ac42f95a91eb1b9eba336c87562dd8aec88347a2177869b32e00 1157916 flatpak-tests_1.16.6-1~deb13u2_armel.deb a4aa1c31da46cbf986a0e577e244d07b593b975e89dcc20a279208c6cca3494d 17483 flatpak_1.16.6-1~deb13u2_armel-buildd.buildinfo 47a71b4c3803f6a84e2a8d7cef48d652eb773887e0b2ae9bcc04831d2c536a6d 1372392 flatpak_1.16.6-1~deb13u2_armel.deb a5fbc285cb20b8eae052dd38892bd1ebd3974cbce138142917667208bb765cd0 29336 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_armel.deb 44c2550cfb3255002318f8fcc9270635886ab51b068f97e3ed76061a9bd864cf 73636 libflatpak-dev_1.16.6-1~deb13u2_armel.deb 9de402946b5af490a6dacedf19f1f01e9beaede152dfaea8bc2d0890c999346b 1717128 libflatpak0-dbgsym_1.16.6-1~deb13u2_armel.deb dd23439bdc2ba0c99d570068a6665050bda11c3bf667a95c66c0b131c893f6eb 332664 libflatpak0_1.16.6-1~deb13u2_armel.deb Files: fcb92bc38e856bc001eb24b90ed47d09 7217124 debug optional flatpak-dbgsym_1.16.6-1~deb13u2_armel.deb c98a85b2df475a0970c6bdfe0fa70e16 10280796 debug optional flatpak-tests-dbgsym_1.16.6-1~deb13u2_armel.deb 1110faad75e57b7f248e5b7120f94897 1157916 misc optional flatpak-tests_1.16.6-1~deb13u2_armel.deb 99f2458ce2251ddbc9dc05c3b0350065 17483 admin optional flatpak_1.16.6-1~deb13u2_armel-buildd.buildinfo 17001d03e01173834f8121a0ae7cecea 1372392 admin optional flatpak_1.16.6-1~deb13u2_armel.deb 1fbbdd4d4c4fbeb4215559e29b1bac46 29336 introspection optional gir1.2-flatpak-1.0_1.16.6-1~deb13u2_armel.deb 6d7b08d2c0c63ea87c52032f433f3b82 73636 libdevel optional libflatpak-dev_1.16.6-1~deb13u2_armel.deb b62d4d3bdf12e32436d9e45e6342f88c 1717128 debug optional libflatpak0-dbgsym_1.16.6-1~deb13u2_armel.deb 16c1975a74ddbdb4b2917f5e3fbf1252 332664 libs optional libflatpak0_1.16.6-1~deb13u2_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEECx5fXZYVNP9tMtwlK1PZBedPspoFAmp7Pi8ACgkQK1PZBedP spod6Q//c79fmgJSwqwVDpta5gA3OPxBtqgCRSj1Wp6g9HdqlS7YB1BfiBfbaUAt 8pwUufeSvdLfPqxb6UwwV0xs5FrT+35vwq1xHiZXUEbkAx1RrjuaaWCN0ZSZe0wJ +uggrUikjJ2QsNdz7Mtq43rjibg1TwybWb+313q11r9SEXWEpN80um10TLhQYjHg r/D+iCq51tT7ytMlJjsB2eLEjy3lPrJuSd1GfzgMjeNKVp5lZdcoveqinJEiiXpW Qov8QOMJ/UaVkU/9sZtC5yzJ9XX+ZToXNHOz4ZEOwbbGkrwlKGqSCI780n6LNJ2f PuEnPBAUjO+dafHpYbTf0JGcc/6fs5ZSMk5D+OHQMn/Luq0vWnfyQc+3n4NWqMLn 2N70G2p7CyKWOcJ3j5SUSReqO3sHRRBOWZPBd7dxqRbFU9ZVb8s+g5rHZeb9/4rs P76bu847+b13aPtq0VmlRZGiLFA9Tc1oirM/5Qk9N1WmQpVdOnvT4WIvmPXt2GVw UsySp0b9OrES0rG0acUPp0eC5wCnfEbaZ5yBJGBkzy+TMhmLSCX4GV9rbY7yD+Cr 8d10YYMSviMs0J6gtnjgCO4CDGwzvbolbzoI1ODYjJa0g/pkPswBzOzv9IGtoiea t1yb2S9Tt5tfQDjqWgMenaXL5Md/0o+gHwgE6nVzNu6fARIHnfY= =RE5n -----END PGP SIGNATURE-----