-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Aug 2026 14:03:38 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: s390x Version: 1.16.6-1~deb13u2 Distribution: trixie-security Urgency: high Maintainer: s390x Build Daemon (zani) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Closes: 1144130 Changes: flatpak (1.16.6-1~deb13u2) trixie-security; urgency=high . * d/patches: Backport security fixes from 1.18.1 (Closes: #1144130) - d/p/libglnx/*.patch: Backport glnx_chase_and_mkdirat() utility function, required by some of the security fixes below - d/p/tests/*.patch: Backport unit tests fixes which are required by the tests for some of the security fixes below - d/p/GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/*.patch: + GHSA-fqx6-vh4p-42cg: Fix writing outside installation directory via crafted commit metadata. A malicious or compromised Flatpak repository could write attacker-controlled files outside /var/lib/flatpak as root. + GHSA-8qxj-x646-phcm: Fix writing outside working directory in `flatpak build-init`. A malicious or compromised SDK could write outside the intended working directory when a developer starts using it for a build. - d/p/GHSA-qrwq-7qwx-q9rp/*.patch: Fix local privilege escalation involving revokefs. A malicious local user could write files outside /var/lib/flatpak as root by tampering with OSTree objects after signature verification. - d/p/GHSA-8688-9x26-hhxj/*.patch: Fix a sandbox escape involving directories inside ~/.var/app/APP_ID. A malicious or compromised Flatpak app could write to arbitrary files outside its sandbox. - d/p/GHSA-99wv-m8rp-g58x/*.patch: Fix a sandbox escape involving the ld.so cache. A malicious or compromised Flatpak app could write files with a fixed name and limited control over content outside the sandbox. - d/p/GHSA-v2gw-v9h5-9q4x/*.patch: Fix local privilege escalation involving crafted OCI architecture names. A malicious local user on a system with an OCI remote configured (unusual on non-Fedora systems) could trick the flatpak-system-helper process into writing outside /var/lib/flatpak. - d/p/GHSA-w69g-9x8j-7p8f/*.patch: Fix reading outside sandbox involving crafted extension metadata. A malicious or compromised Flatpak app could find out whether specific files exist outside the sandbox. - d/p/GHSA-q4gr-vc25-57m5/*.patch: Fix anti-downgrade checks for components installed system-wide. A malicious local user with an active local login session could downgrade an app, runtime or extension to an older, known-vulnerable version and use this to attack other local users. - d/p/GHSA-jr92-2v97-wgvc/*.patch: Fix a buffer overflow when installing or updating from a malicious OCI registry, not believed to be practically exploitable on 64-bit systems. - d/p/hardening/*.patch: Harden file accesses against path traversal, fixing issues that were initially thought to be security vulnerabilities similar to those above, but on further analysis do not seem to be exploitable. - d/p/GHSA-r7hp-698j-2h6c/*.patch: Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts so that GTK accessibility features work as intended. Previously, these accessibility features only worked accidentally as a result of an xdg-dbus-proxy security issue, fixed in 0.1.8. * d/patches: Add additional bug fixes from upstream 1.16.x branch - d/p/subprojects-Ignore-.wraplock-file-generated-by-recent-Mes.patch, d/p/bwrap-Clarify-a-comment.patch, d/p/subprojects-Update-dbus-proxy.wrap-to-v0.1.7.patch: Resync with upstream source, no functional changes - d/p/dir-Use-flatpak_bwrap_child_setup_inherit_fds_cb-to-apply.patch: Silence a spurious warning when apps use the extra_data mechanism - d/p/portal-Actually-use-the-AppInfo-hash-table.patch: Fix a memory leak and potential rare crashes in flatpak-portal Checksums-Sha1: ef590f80d61a5c6fce44feb29a0ade8062a59318 7360092 flatpak-dbgsym_1.16.6-1~deb13u2_s390x.deb 4c9adf95b0c0e3b62be087214ec5851ec9cb35c5 10511436 flatpak-tests-dbgsym_1.16.6-1~deb13u2_s390x.deb ad70b7d1e91e0ef24bc4195d93e968af171dd921 1323024 flatpak-tests_1.16.6-1~deb13u2_s390x.deb 79bea7079e659e68f099c2a0254ce778e8758671 17438 flatpak_1.16.6-1~deb13u2_s390x-buildd.buildinfo f97257c9f1dfbb4e1f7dd67f4d76672d007791f5 1466484 flatpak_1.16.6-1~deb13u2_s390x.deb 433826b2c1c2c9ce86bac9cdf5020e2cebb983d0 29204 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_s390x.deb e408df3f41bccbf7cc8dd6f0716ceb49dfad85d7 73652 libflatpak-dev_1.16.6-1~deb13u2_s390x.deb cced513a79cf3f09d69e2fcf2f2e061ced21656a 1745604 libflatpak0-dbgsym_1.16.6-1~deb13u2_s390x.deb 91009fc4edb8c1d94789449323606b3774d7260b 368140 libflatpak0_1.16.6-1~deb13u2_s390x.deb Checksums-Sha256: 18fc977cef299b585ace3a095c498dc97608efd6d21a857fc4a79624db845505 7360092 flatpak-dbgsym_1.16.6-1~deb13u2_s390x.deb cd6e701ae42d41aa5974b85b17af1e29bd048c364529ae87bb7ec3a280a9e647 10511436 flatpak-tests-dbgsym_1.16.6-1~deb13u2_s390x.deb ce60143f9c4f8dee262e85fe86b7ec853ca93d6f43c51813f91151dfa3775c45 1323024 flatpak-tests_1.16.6-1~deb13u2_s390x.deb e753c345f29ca14908a619185a037d125cd5ca33971033ff3629725b739c1aa5 17438 flatpak_1.16.6-1~deb13u2_s390x-buildd.buildinfo 7d40dc68e2417cc9e6fdbf4560149edff1816124e7d875c976bd0614c12f1170 1466484 flatpak_1.16.6-1~deb13u2_s390x.deb 244574a4bbc9a3c48a72c668e516fc46717e7ee1244632b63a0cf6b592b729c0 29204 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_s390x.deb 755a444da22281587b878db1b8ffebbbf8eb5cbf29e1e2b9eca3426824fb0279 73652 libflatpak-dev_1.16.6-1~deb13u2_s390x.deb a59bc7ab0868d777c7ae11cd04d9af95db26c982a71675a77b656df2383bd05c 1745604 libflatpak0-dbgsym_1.16.6-1~deb13u2_s390x.deb f2ed2c7c2ae3e0b83914ae6a94a994b045b1e9c77788f956c39229b97d9a3945 368140 libflatpak0_1.16.6-1~deb13u2_s390x.deb Files: 8769325cb2eabfa7d08caa579915f9e3 7360092 debug optional flatpak-dbgsym_1.16.6-1~deb13u2_s390x.deb 45217336e27a9207dcb1ca80aef11dba 10511436 debug optional flatpak-tests-dbgsym_1.16.6-1~deb13u2_s390x.deb 56d7a913a97a9e19d85b5dd2750fb3f7 1323024 misc optional flatpak-tests_1.16.6-1~deb13u2_s390x.deb 65d8e5ce69d8dafa9c154c95d9bc8d9a 17438 admin optional flatpak_1.16.6-1~deb13u2_s390x-buildd.buildinfo 555c0afe1e07fc4d86fa23b5560f46d4 1466484 admin optional flatpak_1.16.6-1~deb13u2_s390x.deb df2ecbedd0ea010562b0c8f1dbe89807 29204 introspection optional gir1.2-flatpak-1.0_1.16.6-1~deb13u2_s390x.deb 26b7780288d7f141c7a8916fc0949274 73652 libdevel optional libflatpak-dev_1.16.6-1~deb13u2_s390x.deb 6694589854a24af73f25c8fb1ab37de0 1745604 debug optional libflatpak0-dbgsym_1.16.6-1~deb13u2_s390x.deb 77325486b85b41d726f5da1d9117adf3 368140 libs optional libflatpak0_1.16.6-1~deb13u2_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfUKc1SwkyxlVJBiWHOd5r2LlPicFAmqE2tkACgkQHOd5r2Ll Pic2IxAAokK0sQy4MMOroLw/gSsqlXI9EQOYqGKg8Y4ybIJFiu04af5KoC2Tq5Me h5ALZ4qpMPoheuSg30PifQ17vnu8MBaETq4IfziH/nXNeEDHPaXGVKhf8IxCOGEs Fw9cfkUyVeQhc/eU1Nj6qyupBeGScD10J15iB2fsh/ZDnkFFbaJiNrXHBRbb1xxm /Y6Ez48KePoqfOPfMzb6sea1VGWn09tHmq+q8nrkKIYrmn2VXLMgpRojAbmOvLjw 1QrRt3q23//ZPMEAs541ONx2lQWvr8V2e3MV1nShYNupGOtXK/tnn/sM73XYyZoC ttrHYEKWz5czSN0UGiRwZwz8BydYrLeB5vZd1HBl2ftszi6t59fa1X9Ta3zvCFkd P8/NIXuaHPm8TNKwGQ/DyZ8eNt9lh5Mh1s4Od4FhonrOGypsj2eNrm995m0MURs0 EvE9YqZLQvLApMw7eAJ2Qrrracjfi/UficjpDirXkchK5rIrwuEAi4Q1nqGNOdPg Brn99nyryknVfeWb172hznjvnFENPi+1/SqZJQLXGAtn3Ihbi0sT3hGdBD5CfGsv xyu5pYDwFUDMZWSS9WSD/vldJmMsUIsso66ttMCqI0hvjnDLlntjtVIZORPoKRWK O5sd2wF5u2DLx6MrCfGubiZLKt5wGEYMFh9Pt0G0hntkGQmEg6E= =ayAH -----END PGP SIGNATURE-----