Control: retitle -1 flatpak: not yet updated in LTS
Control: reassign -1 src:flatpak
Control: tags -1 + bookworm bullseye
Control: forwarded -1
https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/436
Control: affects -1 debian-security-support
On Thu, 10 Sep 2026 at 10:01:50 +0000, Holger Levsen wrote:
thanks for this bug report, I guess, but I don't think it's appropriate
to have it filed against debian-security-support.
I'd initially assumed that the LTS team were intentionally not
supporting Flatpak, which would mean the issue could only be resolved by
formalizing that in debian-security-support. But it seems the LTS team
actually does have interest in supporting Flatpak (and they don't have a
pseudo-package of their own), so, yes, reassigning.
LTS team: if you backport a security-fixed Flatpak to older suites, this
bug report (and others) can be closed in that upload.
Doing a similar backport of bubblewrap 0.12.0 is likely to be a
prerequisite for a Flatpak update being practically useful, because
Flatpak is going to be vulnerable to CVE-2026-87766 as long as
bubblewrap isn't fixed, and that's a sandbox escape. There's little
point in fixing vulnerabilities in Flatpak if the sandbox escape via
bubblewrap is still there.
smcv