Control: retitle -1 flatpak: not yet updated in LTS
Control: reassign -1 src:flatpak
Control: tags -1 + bookworm bullseye
Control: forwarded -1 
https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/436
Control: affects -1 debian-security-support

On Thu, 10 Sep 2026 at 10:01:50 +0000, Holger Levsen wrote:
thanks for this bug report, I guess, but I don't think it's appropriate
to have it filed against debian-security-support.

I'd initially assumed that the LTS team were intentionally not supporting Flatpak, which would mean the issue could only be resolved by formalizing that in debian-security-support. But it seems the LTS team actually does have interest in supporting Flatpak (and they don't have a pseudo-package of their own), so, yes, reassigning.

LTS team: if you backport a security-fixed Flatpak to older suites, this bug report (and others) can be closed in that upload.

Doing a similar backport of bubblewrap 0.12.0 is likely to be a prerequisite for a Flatpak update being practically useful, because Flatpak is going to be vulnerable to CVE-2026-87766 as long as bubblewrap isn't fixed, and that's a sandbox escape. There's little point in fixing vulnerabilities in Flatpak if the sandbox escape via bubblewrap is still there.

    smcv

Reply via email to