-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Aug 2026 14:03:38 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: ppc64el Version: 1.16.6-1~deb13u2 Distribution: trixie-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Closes: 1144130 Changes: flatpak (1.16.6-1~deb13u2) trixie-security; urgency=high . * d/patches: Backport security fixes from 1.18.1 (Closes: #1144130) - d/p/libglnx/*.patch: Backport glnx_chase_and_mkdirat() utility function, required by some of the security fixes below - d/p/tests/*.patch: Backport unit tests fixes which are required by the tests for some of the security fixes below - d/p/GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/*.patch: + GHSA-fqx6-vh4p-42cg: Fix writing outside installation directory via crafted commit metadata. A malicious or compromised Flatpak repository could write attacker-controlled files outside /var/lib/flatpak as root. + GHSA-8qxj-x646-phcm: Fix writing outside working directory in `flatpak build-init`. A malicious or compromised SDK could write outside the intended working directory when a developer starts using it for a build. - d/p/GHSA-qrwq-7qwx-q9rp/*.patch: Fix local privilege escalation involving revokefs. A malicious local user could write files outside /var/lib/flatpak as root by tampering with OSTree objects after signature verification. - d/p/GHSA-8688-9x26-hhxj/*.patch: Fix a sandbox escape involving directories inside ~/.var/app/APP_ID. A malicious or compromised Flatpak app could write to arbitrary files outside its sandbox. - d/p/GHSA-99wv-m8rp-g58x/*.patch: Fix a sandbox escape involving the ld.so cache. A malicious or compromised Flatpak app could write files with a fixed name and limited control over content outside the sandbox. - d/p/GHSA-v2gw-v9h5-9q4x/*.patch: Fix local privilege escalation involving crafted OCI architecture names. A malicious local user on a system with an OCI remote configured (unusual on non-Fedora systems) could trick the flatpak-system-helper process into writing outside /var/lib/flatpak. - d/p/GHSA-w69g-9x8j-7p8f/*.patch: Fix reading outside sandbox involving crafted extension metadata. A malicious or compromised Flatpak app could find out whether specific files exist outside the sandbox. - d/p/GHSA-q4gr-vc25-57m5/*.patch: Fix anti-downgrade checks for components installed system-wide. A malicious local user with an active local login session could downgrade an app, runtime or extension to an older, known-vulnerable version and use this to attack other local users. - d/p/GHSA-jr92-2v97-wgvc/*.patch: Fix a buffer overflow when installing or updating from a malicious OCI registry, not believed to be practically exploitable on 64-bit systems. - d/p/hardening/*.patch: Harden file accesses against path traversal, fixing issues that were initially thought to be security vulnerabilities similar to those above, but on further analysis do not seem to be exploitable. - d/p/GHSA-r7hp-698j-2h6c/*.patch: Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts so that GTK accessibility features work as intended. Previously, these accessibility features only worked accidentally as a result of an xdg-dbus-proxy security issue, fixed in 0.1.8. * d/patches: Add additional bug fixes from upstream 1.16.x branch - d/p/subprojects-Ignore-.wraplock-file-generated-by-recent-Mes.patch, d/p/bwrap-Clarify-a-comment.patch, d/p/subprojects-Update-dbus-proxy.wrap-to-v0.1.7.patch: Resync with upstream source, no functional changes - d/p/dir-Use-flatpak_bwrap_child_setup_inherit_fds_cb-to-apply.patch: Silence a spurious warning when apps use the extra_data mechanism - d/p/portal-Actually-use-the-AppInfo-hash-table.patch: Fix a memory leak and potential rare crashes in flatpak-portal Checksums-Sha1: 4a29db763bbd83ffcb91d4d65901d7e79d6a1a00 7631836 flatpak-dbgsym_1.16.6-1~deb13u2_ppc64el.deb 7ff0b6ab0ae3c6b5fad80516db940ff340e90eb6 10849452 flatpak-tests-dbgsym_1.16.6-1~deb13u2_ppc64el.deb 0517ae3eebbff607ef54b235fd01d6547f058c36 1492332 flatpak-tests_1.16.6-1~deb13u2_ppc64el.deb 2ca903a635920b2744c16a905fa2e7c7224e20f2 17666 flatpak_1.16.6-1~deb13u2_ppc64el-buildd.buildinfo cd1ab6cea2b06e7830ad66e0933c47109f14ba25 1581140 flatpak_1.16.6-1~deb13u2_ppc64el.deb a99e7d10c88137816e64c3140acb868963906bfd 29340 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_ppc64el.deb 8d2f729051b608a61a353ee85329e9333ffefd16 73660 libflatpak-dev_1.16.6-1~deb13u2_ppc64el.deb 22b49306094b838ac1a81f3f77762e9bf07ac9ce 1806836 libflatpak0-dbgsym_1.16.6-1~deb13u2_ppc64el.deb 30bcac4e4294281df2b25f21016bd756d709f643 414968 libflatpak0_1.16.6-1~deb13u2_ppc64el.deb Checksums-Sha256: 0923cd913bedf89ac8dc7897a19393ae38eab40b96f14449961aa97291972226 7631836 flatpak-dbgsym_1.16.6-1~deb13u2_ppc64el.deb 2a5d70d6866f264f0f5c808cdf8fc63c23f2680c2b0bc483b993fac8b5aca96a 10849452 flatpak-tests-dbgsym_1.16.6-1~deb13u2_ppc64el.deb 873b776972ea61a41af1fb8c7eec196c06f4681ca6ccbbc51518040a70997e66 1492332 flatpak-tests_1.16.6-1~deb13u2_ppc64el.deb 555f381a99b5ac132e40e3368ae76e3f85b53abbe4eae6ae4afe6661d6ff2b14 17666 flatpak_1.16.6-1~deb13u2_ppc64el-buildd.buildinfo f6dbd2e0da59fec34c61c74b8daf7888608bcd195e172ba9a6f08d0ce7e0fb65 1581140 flatpak_1.16.6-1~deb13u2_ppc64el.deb 4fc9c125ace44efe6da0f376562ed29d4e42971ef0866e992ec0aa64df32ebed 29340 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_ppc64el.deb ea475e9ec1becd252e555f3d0a485516548d8d2a76726fc6d257cff9d395fc03 73660 libflatpak-dev_1.16.6-1~deb13u2_ppc64el.deb 1af12f628178adcc719e424b797714b243348ac392158506dc81205a69622cb2 1806836 libflatpak0-dbgsym_1.16.6-1~deb13u2_ppc64el.deb 026eaf36998f9051ee5fcbf862ab6fc9e2743cb486f43fd0ece5909b1bdc7b14 414968 libflatpak0_1.16.6-1~deb13u2_ppc64el.deb Files: 04a61fbc033293629b6797c547945609 7631836 debug optional flatpak-dbgsym_1.16.6-1~deb13u2_ppc64el.deb 32dc69dfca194d905e0aeadc6bf32fd4 10849452 debug optional flatpak-tests-dbgsym_1.16.6-1~deb13u2_ppc64el.deb 5a20bd5301a1272d456a7d24e3ba60da 1492332 misc optional flatpak-tests_1.16.6-1~deb13u2_ppc64el.deb e9b4d8a61d58d0b0a576db3f7266106a 17666 admin optional flatpak_1.16.6-1~deb13u2_ppc64el-buildd.buildinfo 8743c792b0a672712d266ea7882a02d5 1581140 admin optional flatpak_1.16.6-1~deb13u2_ppc64el.deb b743e5c8176d599565077dddba3f5c40 29340 introspection optional gir1.2-flatpak-1.0_1.16.6-1~deb13u2_ppc64el.deb 3e5609a07846076a34df396804e33175 73660 libdevel optional libflatpak-dev_1.16.6-1~deb13u2_ppc64el.deb 90e05ac1bf79e6cb1c34ee96c43833a7 1806836 debug optional libflatpak0-dbgsym_1.16.6-1~deb13u2_ppc64el.deb d7e54a8b87497d430718ea5573b6707f 414968 libs optional libflatpak0_1.16.6-1~deb13u2_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEySUEQfg5pZeb/U372FRWNm40e2YFAmp7PbcACgkQ2FRWNm40 e2bt4xAAs/2pX9kLXp4kyABUJBA1DviW4As/AXQMfx+LapzZL2qGq+lfxbwBX+tf zYTP2DFnl2ueYbU8dRtcyyUM+bIFW1DxltNplwMbZ409mCrnymJnIYiUaceojYeV j4fPAMms1j1AkshPDf1XPxJgNZwbOqQDv73AxFvspH4wVQSFahRBbrl4i7YOmxCe NycDRWLjlI2VgRcyU47lVVsltfh1fQD9MefpbKTP+tQqfPlXZDt4QU+G1r4KaAKz RgS2/U90qupKtY4B4Qu0oEMHBhpubJdTWPVEU79Hk8IO5LCos2A2GbAiHatr11h+ xsGoSfGif7LGnBAkKopcb/yliNrgNv6PUbyKQmv4a5trLnvy3+x2Wp4By8z+vuKV OP/MQ+DEtE8HrOazYmKcjE6Eb/LHoLu4LQtPEm+7yKI24DnSwUAAJuXJ8QJd2nXb zMfzaA6XELr0tuFo0JibDCXyIWEYZzYuvqHunbzUxhzRdgstTnsWeLhKfhHxN/s+ OPXedhl2YewEwrJFaSjyV8zii+Ya58CWdUVLyb3VudtSBobTTw8S5ZzHBjiBucG7 xu1p0ApyTFl7GerhuNwloTUQG0g25YiQhGsZSUsy/8rCaIwSh96Li/QxHF3nfNNe I2Yk8q3u0sGQv+Bd37L49tQpTxMVISg4r6rfk0ZDhrwLN/tfZio= =VUFe -----END PGP SIGNATURE-----