On Tue, 11 Aug 2026 at 13:32:05 +0100, Simon McVittie wrote:
This bug report is a placeholder for all of the vulnerabilities that are
fixed in prerelease 1.19.0. The same vulnerabilities will also be fixed
in a 1.18.1 stable release, soon. More details when they are available.

https://github.com/flatpak/flatpak/releases/tag/1.18.1 lists all the vulnerabilities. We don't have CVE IDs for any of them yet, so they're referenced by GHSA- IDs.

The most serious are a full sandbox escape (GHSA-8688-9x26-hhxj) and local root privilege escalation (GHSA-qrwq-7qwx-q9rp, GHSA-fqx6-vh4p-42cg).

I will upload 1.18.1 to unstable soon: automated tests are still running, but manual testing was successful.

All of the vulnerabilities except for GHSA-9rww-v4mm-x4jg affect trixie as well. GHSA-9rww-v4mm-x4jg is a problem with a new feature that was added in the 1.17.x/1.18.x cycle, so trixie is not vulnerable to it.

https://people.debian.org/~smcv/bug1144130/trixie/ contains backported fixes for trixie, covering everything except GHSA-9rww-v4mm-x4jg. As discussed by private email with the security team, this also includes pending upstream non-security bug fixes from the flatpak-1.16.x branch. May I upload?

For convenience, https://people.debian.org/~smcv/bug1144130/trixie/rc/ contains source and amd64 binaries for a functionally equivalent test-build (the only difference is the changelog).

Thanks,
    smcv

Reply via email to