-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Aug 2026 14:03:38 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: i386 Version: 1.16.6-1~deb13u2 Distribution: trixie-security Urgency: high Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Closes: 1144130 Changes: flatpak (1.16.6-1~deb13u2) trixie-security; urgency=high . * d/patches: Backport security fixes from 1.18.1 (Closes: #1144130) - d/p/libglnx/*.patch: Backport glnx_chase_and_mkdirat() utility function, required by some of the security fixes below - d/p/tests/*.patch: Backport unit tests fixes which are required by the tests for some of the security fixes below - d/p/GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/*.patch: + GHSA-fqx6-vh4p-42cg: Fix writing outside installation directory via crafted commit metadata. A malicious or compromised Flatpak repository could write attacker-controlled files outside /var/lib/flatpak as root. + GHSA-8qxj-x646-phcm: Fix writing outside working directory in `flatpak build-init`. A malicious or compromised SDK could write outside the intended working directory when a developer starts using it for a build. - d/p/GHSA-qrwq-7qwx-q9rp/*.patch: Fix local privilege escalation involving revokefs. A malicious local user could write files outside /var/lib/flatpak as root by tampering with OSTree objects after signature verification. - d/p/GHSA-8688-9x26-hhxj/*.patch: Fix a sandbox escape involving directories inside ~/.var/app/APP_ID. A malicious or compromised Flatpak app could write to arbitrary files outside its sandbox. - d/p/GHSA-99wv-m8rp-g58x/*.patch: Fix a sandbox escape involving the ld.so cache. A malicious or compromised Flatpak app could write files with a fixed name and limited control over content outside the sandbox. - d/p/GHSA-v2gw-v9h5-9q4x/*.patch: Fix local privilege escalation involving crafted OCI architecture names. A malicious local user on a system with an OCI remote configured (unusual on non-Fedora systems) could trick the flatpak-system-helper process into writing outside /var/lib/flatpak. - d/p/GHSA-w69g-9x8j-7p8f/*.patch: Fix reading outside sandbox involving crafted extension metadata. A malicious or compromised Flatpak app could find out whether specific files exist outside the sandbox. - d/p/GHSA-q4gr-vc25-57m5/*.patch: Fix anti-downgrade checks for components installed system-wide. A malicious local user with an active local login session could downgrade an app, runtime or extension to an older, known-vulnerable version and use this to attack other local users. - d/p/GHSA-jr92-2v97-wgvc/*.patch: Fix a buffer overflow when installing or updating from a malicious OCI registry, not believed to be practically exploitable on 64-bit systems. - d/p/hardening/*.patch: Harden file accesses against path traversal, fixing issues that were initially thought to be security vulnerabilities similar to those above, but on further analysis do not seem to be exploitable. - d/p/GHSA-r7hp-698j-2h6c/*.patch: Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts so that GTK accessibility features work as intended. Previously, these accessibility features only worked accidentally as a result of an xdg-dbus-proxy security issue, fixed in 0.1.8. * d/patches: Add additional bug fixes from upstream 1.16.x branch - d/p/subprojects-Ignore-.wraplock-file-generated-by-recent-Mes.patch, d/p/bwrap-Clarify-a-comment.patch, d/p/subprojects-Update-dbus-proxy.wrap-to-v0.1.7.patch: Resync with upstream source, no functional changes - d/p/dir-Use-flatpak_bwrap_child_setup_inherit_fds_cb-to-apply.patch: Silence a spurious warning when apps use the extra_data mechanism - d/p/portal-Actually-use-the-AppInfo-hash-table.patch: Fix a memory leak and potential rare crashes in flatpak-portal Checksums-Sha1: b2a1fa7d8ef6ebe2dde75f372ac26321746c4e86 6499828 flatpak-dbgsym_1.16.6-1~deb13u2_i386.deb 7971234508127f37a9b5201828673fb1e053c991 9265968 flatpak-tests-dbgsym_1.16.6-1~deb13u2_i386.deb e16e8054ef67888fc77ddc021ff7f9c7004ec53a 1477500 flatpak-tests_1.16.6-1~deb13u2_i386.deb ce90fcbe93e3667a9a2f8390940b56faaade21a1 17511 flatpak_1.16.6-1~deb13u2_i386-buildd.buildinfo 30a94a06316f6565aafef8e273737157066e667d 1603332 flatpak_1.16.6-1~deb13u2_i386.deb ccc91045b33be3230ba10f236e3d12c1deff201c 29344 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_i386.deb 0f95f5798a042ab2ffcbca7836ba1b96ef42f692 73648 libflatpak-dev_1.16.6-1~deb13u2_i386.deb 90c122f6cc3361a52475ceda6b4462c47b86a8f4 1499988 libflatpak0-dbgsym_1.16.6-1~deb13u2_i386.deb b1ee4ae9678033eb882ea27b1a1b50ce127cbbef 426592 libflatpak0_1.16.6-1~deb13u2_i386.deb Checksums-Sha256: 15d779c3bdb7d33cb54a1952a834ffbea79c3668ee1bb3e32c30a1841cb23890 6499828 flatpak-dbgsym_1.16.6-1~deb13u2_i386.deb 919a98375197b1e71c3e35ee3e9c862c0ac209381ff90d74ccffc680b2495a3a 9265968 flatpak-tests-dbgsym_1.16.6-1~deb13u2_i386.deb cbbdbf475ceb81aa7cc3d95b8ced1c4f003471a74791b999ddbe94dbcbd90476 1477500 flatpak-tests_1.16.6-1~deb13u2_i386.deb 727705d81f053d3170fa48ab4e22cbff02081b52f8c8562f1dbff7468d24ca89 17511 flatpak_1.16.6-1~deb13u2_i386-buildd.buildinfo 332ce759a38a19708cce8dcf8d0bd0d22caf747df951391cbc35ce30515eb387 1603332 flatpak_1.16.6-1~deb13u2_i386.deb 8c0383a00d46bea65f58ad874987a6d8a020045dff92b2bb6997f8519eca57fc 29344 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_i386.deb b281a1a025e1f9c8c9fc6dbad74ed199bbf13158c6208888f95ed408640c10ce 73648 libflatpak-dev_1.16.6-1~deb13u2_i386.deb 15501f4c366007f6180afc52f49de8064fbad7a8213a092d8aaf5e659a680d1a 1499988 libflatpak0-dbgsym_1.16.6-1~deb13u2_i386.deb 1fffb79bdd71f6c76666e3045d1be00c46d96cfe1dd808d8becbee2264230383 426592 libflatpak0_1.16.6-1~deb13u2_i386.deb Files: 38f1b880b3dbe68daaf879bde37d22ec 6499828 debug optional flatpak-dbgsym_1.16.6-1~deb13u2_i386.deb 6020e70afd40f53ab0c27878b985d628 9265968 debug optional flatpak-tests-dbgsym_1.16.6-1~deb13u2_i386.deb 50cbee670d04de07df540304a66656c1 1477500 misc optional flatpak-tests_1.16.6-1~deb13u2_i386.deb 15283635968dc2d88e027ab6b03c9555 17511 admin optional flatpak_1.16.6-1~deb13u2_i386-buildd.buildinfo 55f55ca8fe5c1d9e7edea85e45d3519b 1603332 admin optional flatpak_1.16.6-1~deb13u2_i386.deb bec55ee093dd834e73716e062ebe46f1 29344 introspection optional gir1.2-flatpak-1.0_1.16.6-1~deb13u2_i386.deb 3dd2af84014fafdc67e9b6499ba38965 73648 libdevel optional libflatpak-dev_1.16.6-1~deb13u2_i386.deb a1b5ffbf5941939d7377b04df796cab5 1499988 debug optional libflatpak0-dbgsym_1.16.6-1~deb13u2_i386.deb 68ec927fc66f88026598eab3445ffd67 426592 libs optional libflatpak0_1.16.6-1~deb13u2_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEPAUaMA0H0rOy6qBWf2INRiCdaWIFAmp7PbUACgkQf2INRiCd aWLssA/+J+eisi91TBF1APrZ8g36A8CRECzbcIEkzAuvxnySS8RpAXK3HQzUFgdb swzaR3RKEyVkpqHn1QfJUjkXd4fyzRFrch4R7zBWYChRck27g2ykR9d6yl5OQND9 dxPeLrWSyzZSxLnxPgv+ZipnBAJbm25NfLPMAOWneMTDN00kmpuxcAaNVk4dGYPO TFM3mCnoBSdIuWMXmxPKO6+fMdXvwZ+9AL6bmeLoKrKesU4wwlaynCKH8ymFJnO9 gBk6upKZ+bhTuYsMc2KrLMfp1C3UYnl6riWOdMcT9G1LVQNiCGhQVEun/m9owkyj PGvMCh9MrInQ8NNVZfZCN3+QHPn5KJVKUcAXKfXCufGW1uo7gj7Td11OJbBnfwDo FlhOSagfu3Q2Mm5vroplYUxPVrHzbT3E93hbxaRXFaAdyfxpKUvTANy77Fq+PsoT 6wcx5pgsr42refCWwgRlJrQD6bJ2fSMhr/mA1w/CPanNiKudEpxL25ZURCTKg/Of S8BBiGmAYomM4K/20d94wCyjxIItElOEQvbLSb3TwwAArbRtBEeXV2zmbb61xS2n hSVAQ9FxQWMZXQBAOIhC1Quovnf6cQ+HU8tHEwas0vZSidt6aOluj+OjiBZYB7hW oe5ahxnHM/BXiYe5EEn8VEeTJZ8x8NdQgIIwpHijN3uteJJJd1o= =trPA -----END PGP SIGNATURE-----