-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Aug 2026 14:03:38 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: riscv64 Version: 1.16.6-1~deb13u2 Distribution: trixie-security Urgency: high Maintainer: riscv64 Build Daemon (rv-osuosl-03) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Closes: 1144130 Changes: flatpak (1.16.6-1~deb13u2) trixie-security; urgency=high . * d/patches: Backport security fixes from 1.18.1 (Closes: #1144130) - d/p/libglnx/*.patch: Backport glnx_chase_and_mkdirat() utility function, required by some of the security fixes below - d/p/tests/*.patch: Backport unit tests fixes which are required by the tests for some of the security fixes below - d/p/GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/*.patch: + GHSA-fqx6-vh4p-42cg: Fix writing outside installation directory via crafted commit metadata. A malicious or compromised Flatpak repository could write attacker-controlled files outside /var/lib/flatpak as root. + GHSA-8qxj-x646-phcm: Fix writing outside working directory in `flatpak build-init`. A malicious or compromised SDK could write outside the intended working directory when a developer starts using it for a build. - d/p/GHSA-qrwq-7qwx-q9rp/*.patch: Fix local privilege escalation involving revokefs. A malicious local user could write files outside /var/lib/flatpak as root by tampering with OSTree objects after signature verification. - d/p/GHSA-8688-9x26-hhxj/*.patch: Fix a sandbox escape involving directories inside ~/.var/app/APP_ID. A malicious or compromised Flatpak app could write to arbitrary files outside its sandbox. - d/p/GHSA-99wv-m8rp-g58x/*.patch: Fix a sandbox escape involving the ld.so cache. A malicious or compromised Flatpak app could write files with a fixed name and limited control over content outside the sandbox. - d/p/GHSA-v2gw-v9h5-9q4x/*.patch: Fix local privilege escalation involving crafted OCI architecture names. A malicious local user on a system with an OCI remote configured (unusual on non-Fedora systems) could trick the flatpak-system-helper process into writing outside /var/lib/flatpak. - d/p/GHSA-w69g-9x8j-7p8f/*.patch: Fix reading outside sandbox involving crafted extension metadata. A malicious or compromised Flatpak app could find out whether specific files exist outside the sandbox. - d/p/GHSA-q4gr-vc25-57m5/*.patch: Fix anti-downgrade checks for components installed system-wide. A malicious local user with an active local login session could downgrade an app, runtime or extension to an older, known-vulnerable version and use this to attack other local users. - d/p/GHSA-jr92-2v97-wgvc/*.patch: Fix a buffer overflow when installing or updating from a malicious OCI registry, not believed to be practically exploitable on 64-bit systems. - d/p/hardening/*.patch: Harden file accesses against path traversal, fixing issues that were initially thought to be security vulnerabilities similar to those above, but on further analysis do not seem to be exploitable. - d/p/GHSA-r7hp-698j-2h6c/*.patch: Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts so that GTK accessibility features work as intended. Previously, these accessibility features only worked accidentally as a result of an xdg-dbus-proxy security issue, fixed in 0.1.8. * d/patches: Add additional bug fixes from upstream 1.16.x branch - d/p/subprojects-Ignore-.wraplock-file-generated-by-recent-Mes.patch, d/p/bwrap-Clarify-a-comment.patch, d/p/subprojects-Update-dbus-proxy.wrap-to-v0.1.7.patch: Resync with upstream source, no functional changes - d/p/dir-Use-flatpak_bwrap_child_setup_inherit_fds_cb-to-apply.patch: Silence a spurious warning when apps use the extra_data mechanism - d/p/portal-Actually-use-the-AppInfo-hash-table.patch: Fix a memory leak and potential rare crashes in flatpak-portal Checksums-Sha1: 648b7301777d1983b67bc4a4ec8817b036a4abaa 7093060 flatpak-dbgsym_1.16.6-1~deb13u2_riscv64.deb 0210e442b857529f0200fdaaaacb433f2a4c2876 10164996 flatpak-tests-dbgsym_1.16.6-1~deb13u2_riscv64.deb bc9609419b4d43e03b1811289ff88f26264296b7 1443276 flatpak-tests_1.16.6-1~deb13u2_riscv64.deb b1bd391574e83e0be51421cf18957da2c859de08 17637 flatpak_1.16.6-1~deb13u2_riscv64-buildd.buildinfo 85d4aa1b20b7472a8b8d49d1aabdf9bf56676280 1557592 flatpak_1.16.6-1~deb13u2_riscv64.deb a4bbf3f563b3567ab0ebc35c9a6dd8ad11ac0f7e 29332 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_riscv64.deb 3f7024958ac643a9748a4d8e2227af41195d083a 73628 libflatpak-dev_1.16.6-1~deb13u2_riscv64.deb 095969306830a1e2f36ae868d3fd26c676466a75 1628668 libflatpak0-dbgsym_1.16.6-1~deb13u2_riscv64.deb 0276fa2d160f2267713a9ffc0fac3f6b269b7d4d 393316 libflatpak0_1.16.6-1~deb13u2_riscv64.deb Checksums-Sha256: 31a70f5eb05c23aa222dacf6cba9b74e97d829ef95fa903410e313a964aa6133 7093060 flatpak-dbgsym_1.16.6-1~deb13u2_riscv64.deb cc749e918d0a159083e3447510deab74eeddd94480571fdb2a8cefbabc4c400c 10164996 flatpak-tests-dbgsym_1.16.6-1~deb13u2_riscv64.deb 98633a1e7d43c15162a658f39ba3e9728c62ca5b986afe2aa29929b2d2f99177 1443276 flatpak-tests_1.16.6-1~deb13u2_riscv64.deb f719dc0a81b30cddeeefe6c67bd4a97ffafc9033be39e49d055d1317b2299f65 17637 flatpak_1.16.6-1~deb13u2_riscv64-buildd.buildinfo c8c28ba407994d513c95a125f873f30f4f554d7cde1d549cd7a041580baf07c5 1557592 flatpak_1.16.6-1~deb13u2_riscv64.deb 1cfbd2495d06443c8b98bd089651407f87c00f4c692f7610e406a4bb8ad575f8 29332 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_riscv64.deb 00a1c513e8acffedaf85122a611549059f4a4a0fd9b82a250ac7954606ed05c1 73628 libflatpak-dev_1.16.6-1~deb13u2_riscv64.deb 99f1bfd051a790f5144d5c380654dc1da99e8b5bf8c76dfa56f9b78746c6c982 1628668 libflatpak0-dbgsym_1.16.6-1~deb13u2_riscv64.deb c69237deaf4e13b234a8edd0046f3602f8da4291a61bec26517de70f633bd0bd 393316 libflatpak0_1.16.6-1~deb13u2_riscv64.deb Files: 6b8fb43519421e66b84ce0d571bc05bd 7093060 debug optional flatpak-dbgsym_1.16.6-1~deb13u2_riscv64.deb 6b86254af58855e5f78629e84f0c7fbf 10164996 debug optional flatpak-tests-dbgsym_1.16.6-1~deb13u2_riscv64.deb ad7da8fdd645024d377cd644e2ca11c8 1443276 misc optional flatpak-tests_1.16.6-1~deb13u2_riscv64.deb 150d3970ce64c0c15f1c0f3ae6c413b1 17637 admin optional flatpak_1.16.6-1~deb13u2_riscv64-buildd.buildinfo 56abac9327466f9fd36225ac35ca8a66 1557592 admin optional flatpak_1.16.6-1~deb13u2_riscv64.deb 5630c598bb165c6727373a01b02efc42 29332 introspection optional gir1.2-flatpak-1.0_1.16.6-1~deb13u2_riscv64.deb 1c1917310a99f5315d23241ea4d0d90e 73628 libdevel optional libflatpak-dev_1.16.6-1~deb13u2_riscv64.deb c97eb0c52e9a17e757288c10dcd71265 1628668 debug optional libflatpak0-dbgsym_1.16.6-1~deb13u2_riscv64.deb b6705c72d499dc55e101ea9d9ebb3afe 393316 libs optional libflatpak0_1.16.6-1~deb13u2_riscv64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEExv8RwtKAmv8J56r/6ETk30hvxtkFAmp7QxUACgkQ6ETk30hv xtmGXw/+IPdvETHNtcksAQl9ls4xxuYVVRtFE2yZpWEBI9E1JTecY4TaENpPh3m0 TVhxXOBj9pZPqTpzaREl0gnrbN2mirRcx5QqOJOYe8ATWs4f3W+tdwpzeqmmJnKa KCT0Lv9aceu/Ly0gvUyDqVc5JsPvxzcQj8/prqTlTnECRXA+wcYVhYOiqRMu8KCy PdNl3FVSQc57FGIgHNH2F40jkdL4CY39XYeFduFjLq9ZUu6sKVDHdseZIvwdmDrV rJH1G9kbUx7sWeor5x4umJGP8zHTt9KXb0UKLTdRJOHfEalamkdjVDFVP3P/F7Nu 68tzHZgnVHatTphqEbm/XWlG+aBBwzOXsAQM7daNw19FEFqAML/M7KuWoNbfCxaY V72r/S9Z/RvWEUHA54Bg8caqbrxR5pK+aycdzik+gjn8oxePpkkPMhfFl//FIjMx JeexKC7enYtXVpz+/+S4X4kUKgYsTQzWKXJUpqx0ggjNilJF1d/22o4mZd9uXQLF yNd8s/sdmL3Xg8C0X48s3T7ZAch26QSQz1pTfDv5A0m9v0oYEG2JNJxF6nsfZOLA YHdIU15v1PMKCWYfWWSEjiyIkvFWovTwlw5Q9mkvt2cBnbwgYJRLdqb7fMtApqIT y8s5l+yghEPBf/lwG8owVlwbJoXBE1NQKilY5B3dBBmBv+ZhsQ8= =osTC -----END PGP SIGNATURE-----