-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Aug 2026 14:03:38 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: armhf Version: 1.16.6-1~deb13u2 Distribution: trixie-security Urgency: high Maintainer: armhf Build Daemon (arm-ubc-06) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Closes: 1144130 Changes: flatpak (1.16.6-1~deb13u2) trixie-security; urgency=high . * d/patches: Backport security fixes from 1.18.1 (Closes: #1144130) - d/p/libglnx/*.patch: Backport glnx_chase_and_mkdirat() utility function, required by some of the security fixes below - d/p/tests/*.patch: Backport unit tests fixes which are required by the tests for some of the security fixes below - d/p/GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/*.patch: + GHSA-fqx6-vh4p-42cg: Fix writing outside installation directory via crafted commit metadata. A malicious or compromised Flatpak repository could write attacker-controlled files outside /var/lib/flatpak as root. + GHSA-8qxj-x646-phcm: Fix writing outside working directory in `flatpak build-init`. A malicious or compromised SDK could write outside the intended working directory when a developer starts using it for a build. - d/p/GHSA-qrwq-7qwx-q9rp/*.patch: Fix local privilege escalation involving revokefs. A malicious local user could write files outside /var/lib/flatpak as root by tampering with OSTree objects after signature verification. - d/p/GHSA-8688-9x26-hhxj/*.patch: Fix a sandbox escape involving directories inside ~/.var/app/APP_ID. A malicious or compromised Flatpak app could write to arbitrary files outside its sandbox. - d/p/GHSA-99wv-m8rp-g58x/*.patch: Fix a sandbox escape involving the ld.so cache. A malicious or compromised Flatpak app could write files with a fixed name and limited control over content outside the sandbox. - d/p/GHSA-v2gw-v9h5-9q4x/*.patch: Fix local privilege escalation involving crafted OCI architecture names. A malicious local user on a system with an OCI remote configured (unusual on non-Fedora systems) could trick the flatpak-system-helper process into writing outside /var/lib/flatpak. - d/p/GHSA-w69g-9x8j-7p8f/*.patch: Fix reading outside sandbox involving crafted extension metadata. A malicious or compromised Flatpak app could find out whether specific files exist outside the sandbox. - d/p/GHSA-q4gr-vc25-57m5/*.patch: Fix anti-downgrade checks for components installed system-wide. A malicious local user with an active local login session could downgrade an app, runtime or extension to an older, known-vulnerable version and use this to attack other local users. - d/p/GHSA-jr92-2v97-wgvc/*.patch: Fix a buffer overflow when installing or updating from a malicious OCI registry, not believed to be practically exploitable on 64-bit systems. - d/p/hardening/*.patch: Harden file accesses against path traversal, fixing issues that were initially thought to be security vulnerabilities similar to those above, but on further analysis do not seem to be exploitable. - d/p/GHSA-r7hp-698j-2h6c/*.patch: Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts so that GTK accessibility features work as intended. Previously, these accessibility features only worked accidentally as a result of an xdg-dbus-proxy security issue, fixed in 0.1.8. * d/patches: Add additional bug fixes from upstream 1.16.x branch - d/p/subprojects-Ignore-.wraplock-file-generated-by-recent-Mes.patch, d/p/bwrap-Clarify-a-comment.patch, d/p/subprojects-Update-dbus-proxy.wrap-to-v0.1.7.patch: Resync with upstream source, no functional changes - d/p/dir-Use-flatpak_bwrap_child_setup_inherit_fds_cb-to-apply.patch: Silence a spurious warning when apps use the extra_data mechanism - d/p/portal-Actually-use-the-AppInfo-hash-table.patch: Fix a memory leak and potential rare crashes in flatpak-portal Checksums-Sha1: ec5ffa7e157209f411dc7dcc4685ec0b7dc21bde 7213936 flatpak-dbgsym_1.16.6-1~deb13u2_armhf.deb 2ddde1dad31adee9f5adad5a79c3ef72fffdaa65 10251708 flatpak-tests-dbgsym_1.16.6-1~deb13u2_armhf.deb b301fba40f14eb80bc64324d84c4e05a463a7df6 1179400 flatpak-tests_1.16.6-1~deb13u2_armhf.deb a4efce987907c59014b654f947ad5ee76e7f970b 17497 flatpak_1.16.6-1~deb13u2_armhf-buildd.buildinfo 31605184e7dacaf22dcfb11753f259deb014b6ed 1386656 flatpak_1.16.6-1~deb13u2_armhf.deb b8f3c04f375c638813ab465ce7235c57688d51bb 29328 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_armhf.deb 3e5d01ca3a992fea1fb495c24fa7b0810a492ea9 73636 libflatpak-dev_1.16.6-1~deb13u2_armhf.deb 5e25da0066844e4d87af32d545f81f10db8e93ec 1715140 libflatpak0-dbgsym_1.16.6-1~deb13u2_armhf.deb de4dbe0fde9cf83e9731af5038e3f7f0a79603ae 339652 libflatpak0_1.16.6-1~deb13u2_armhf.deb Checksums-Sha256: b036af6ff786f4160333b77b67673ab9fb8204352a1b5a6f996bebe2e2b38472 7213936 flatpak-dbgsym_1.16.6-1~deb13u2_armhf.deb b385abdc92cbc72a7b4b88676b71c5708b296b654eb6d6327f46d6d19bd441e6 10251708 flatpak-tests-dbgsym_1.16.6-1~deb13u2_armhf.deb b164b9a5a59c128a0ae8117b27790a7686498f84105efefb4bc261e3b726555f 1179400 flatpak-tests_1.16.6-1~deb13u2_armhf.deb 6c9ad099ebb4bebee9ee4e4433f591752becd26a15d936b1029d3c21f53b664e 17497 flatpak_1.16.6-1~deb13u2_armhf-buildd.buildinfo b727b5b1b9e0dbc8ec23165629a488b0091865dea5f113cc9db6942c89fa2fa9 1386656 flatpak_1.16.6-1~deb13u2_armhf.deb 08050f2e10f058e8e18317fa1c5488891d55496f78a63c3b25d2692717606b0a 29328 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_armhf.deb 7a4340623d74018bd9de9724b9b6c4c6cc12edd28f30cd62b8402ec9b43b235b 73636 libflatpak-dev_1.16.6-1~deb13u2_armhf.deb f085cd9ac03a1020f49e3cec8918dff87b0888af81ecb2871e5ff8d51ecc1119 1715140 libflatpak0-dbgsym_1.16.6-1~deb13u2_armhf.deb 8b94febad88a863c782e7b79a0fdd0a319c6d4b8e1896dcaeabd0f97e4f1dcb7 339652 libflatpak0_1.16.6-1~deb13u2_armhf.deb Files: 3f703d0e892d2dbb82b90b6f357e10a3 7213936 debug optional flatpak-dbgsym_1.16.6-1~deb13u2_armhf.deb 949c15bfc48108071c76de43d2920f66 10251708 debug optional flatpak-tests-dbgsym_1.16.6-1~deb13u2_armhf.deb 2b62ea4171729c143fa17aa58e91bee8 1179400 misc optional flatpak-tests_1.16.6-1~deb13u2_armhf.deb f78de78caad38b80de69d0a28e0c7546 17497 admin optional flatpak_1.16.6-1~deb13u2_armhf-buildd.buildinfo c759e97f9b2a3de953db5773ed86bed1 1386656 admin optional flatpak_1.16.6-1~deb13u2_armhf.deb 9ce3a4c57affc985280b88d84ed9772a 29328 introspection optional gir1.2-flatpak-1.0_1.16.6-1~deb13u2_armhf.deb 66a6666999ef54dee3860e59c91202c9 73636 libdevel optional libflatpak-dev_1.16.6-1~deb13u2_armhf.deb 7ce8871fc5fa6000bcdf35028ab23f07 1715140 debug optional libflatpak0-dbgsym_1.16.6-1~deb13u2_armhf.deb e7876cbdc3e398f23379edf692f17d42 339652 libs optional libflatpak0_1.16.6-1~deb13u2_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBOUsBrtd5lcy6oRfutMAkCxKbL0FAmp7PgkACgkQutMAkCxK bL0u5A//RhU48Nyl//sE47CdGs2y4ybuBhToDM7GpJYQL1an80ubIBUyPqaGRzq/ zbXGbGdEj1t9Itey5zVgPNbz8B1OJi5TSqirygaZUNQmsz+ewqx2Hd4alod40s32 k6No6xbojTIoW4np6rcuGovHxnitU92/nIbi6AmdTUuNnFxL0jN81rw4LzQwIyZ7 lzBLJ0L0KY86srD5jYW1yi60Jgrb9krba9ckgI0yxB73YvXe7pT4GNSPemPN68eD NSiu3AKQjhX37ZWPhmOz3FPLC4z/cCAqXgCVBzraqdYgtRYPnyLGDyIKCz6zuDBS ndhoeYrSXNMKg+wQVFbAol/eVhMV5ka+dXLz5HcNTkncYBdPgOoYZfPbeRa+KTY+ fp1ZcGi/9FlbX8A7fnrOmJr8TECGLLTrdGdsZ6I7MV+byNqwtRO1Xs6+ulV6FxJb brNxDfSO79xs19odlKh4vGTTxk2FXgoc0UTNNmVlLhUEH568IJR2ULBTGzXIkm3T INhxjEhHLu8r3CJZEeYSzswmCKWZzBlj8bZ2sqoLiY4zAkj9iw7aiil621XZfzcV TJBKTa0NtJAFVbpdoekxmo5B2o7pfyCBzT3XPlV8TA3vMjLhoZnBZG88Kzvyt5O3 UI31Cw3bDUBuxKcQFvqfX/XLb1EuAnnXw0xRvb8grnjx++DvBIg= =oCyT -----END PGP SIGNATURE-----