Package: debian-security-support
Severity: normal
X-Debbugs-Cc: [email protected], [email protected]
Control: affects -1 + flatpak

The version of Flatpak in bookworm has multiple security 
vulnerabilities, including 
https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj 
(sandbox escape) and 
https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj 
(root priilege escalation). There is also an indirect sandbox escape via 
a bubblewrap issue 
(https://security-tracker.debian.org/tracker/CVE-2026-87766) which has 
been marked as ignored for bookworm. Similarly, by the time bullseye LTS 
reached end-of-life, there were several known unfixed vulnerabilities in 
bullseye's Flatpak.

Unfortunately I don't think it will be feasible to address these 
vulnerabilities without either backporting the newer upstream version 
from trixie, or backporting so many changes that a new upstream version 
would actually have been lower-risk.

At the same time, if users are running a LTS distribution on 
desktop-class systems, an app-container technology like Flatpak can be a 
useful way to get versions of apps that are newer than those offered as 
part of the OS itself, without having to upgrade the OS or backport 
individual libraries. Does the LTS team see Debian LTS as being for 
servers, or for desktops, or both?

I think there are two routes that the LTS team could reasonably take for 
Flatpak:

- support Flatpak by backporting what's necessary even if that's
  sometimes a new upstream release, as is done for some web browsers;

- or explicitly de-support Flatpak in debian-security-support

If the LTS team does want to backport newer upstream releases of Flatpak 
from trixie (or perhaps even from unstable) for use on LTS desktop 
systems, they're welcome to use the debian/bookworm and debian/bullseye 
branches in https://salsa.debian.org/debian/flatpak, and/or base a 
backport on what was in bookworm-backports before it closed. Flatpak is 
designed to be buildable on relatively old distributions, so this is 
usually a matter of reverting increasingly many of the changes in 
debian/ as a version gets backported further into the past: the latest 
upstream releases will only rarely need backport-specific changes.

https://launchpad.net/~flatpak/+archive/ubuntu/stable, 
https://github.com/flatpak/ppa-flatpak, 
https://github.com/flatpak/ppa-bubblewrap have some mostly-up-to-date 
backports as far as Ubuntu 20.04 which could be used for inspiration.
If there happens to be a Debian/Ubuntu developer who can take over 
responsibility for updating the PPA, I'd welcome help there - I don't 
use Ubuntu myself, except on test systems.

I am not able to take responsibility for Flatpak in LTS myself, sorry: 
the releases covered by the security team are as far as I'm able to go 
(and oldstable, during the 1 year support overlap, isn't always feasible 
with normal Debian policies either).

    smcv

Reply via email to