*** This bug is a security vulnerability ***

Public security bug reported:

Upstream advisory:
https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj

This is one of several vulnerabilities fixed in 1.18.1 upstream:
https://www.openwall.com/lists/oss-security/2026/08/11/9

The 1.16.x branch is no longer supported upstream and will not receive
new releases, but backports of the 1.18.1 security fixes are available
in the flatpak-1.16.x branch upstream, and in Debian 13.

Ubuntu 26.04 LTS 'resolute' currently ships Flatpak 1.16.6. If
backporting 1.18.x is not acceptable, then I would recommend updating
the package to be equivalent to what's in Debian 13 security update
https://lists.debian.org/debian-security-announce/2026/msg00343.html
(and then keeping it in sync with what's in Debian 13 security updates
in future).

Older LTS branches ship older branches of Flatpak (1.14.x or older) and
already had several known unfixed vulnerabilities. The Flatpak upstream
developers are not going to backport security fixes to these old
branches. If Ubuntu policy is to stick to these older branches, then
Ubuntu developers will have to be responsible for their security status
- either backporting a newer upstream release, or backporting individual
security fixes, or flagging these older versions as end-of-life and
warning Ubuntu users not to use them.

Flatpak is security-sensitive software and I think it's important to be
realistic about the extent to which older branches can be supported,
especially with LLMs hammering all of the world's software looking for
security vulnerabilities that they can exploit.

The Debian LTS team appears to be considering backporting newer Flatpak
versions like 1.16.6 into older Debian LTS releases instead of
attempting to backport individual security fixes:
<https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/436>.
It might be wise for Ubuntu to do similarly.

An unofficial backport of modern versions of Flatpak is available in a
PPA: <https://launchpad.net/~flatpak/+archive/ubuntu/stable>,
<https://github.com/flatpak/ppa-flatpak>. This does not come with any
support guarantees, but if nothing else it provides a proof of concept
illustrating how an Ubuntu developer could provide a more up-to-date
version of Flatpak.

** Affects: flatpak (Ubuntu)
     Importance: Undecided
         Status: New

** Information type changed from Private Security to Public Security

** CVE added: https://cve.org/CVERecord?id=CVE-2026-90616

** Description changed:

  Upstream advisory:
  https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj
  
  This is one of several vulnerabilities fixed in 1.18.1 upstream:
  https://www.openwall.com/lists/oss-security/2026/08/11/9
  
  The 1.16.x branch is no longer supported upstream and will not receive
  new releases, but backports of the 1.18.1 security fixes are available
  in the flatpak-1.16.x branch upstream, and in Debian 13.
  
  Ubuntu 26.04 LTS 'resolute' currently ships Flatpak 1.16.6. If
  backporting 1.18.x is not acceptable, then I would recommend updating
  the package to be equivalent to what's in Debian 13 security update
  https://lists.debian.org/debian-security-announce/2026/msg00343.html
  (and then keeping it in sync with what's in Debian 13 security updates
  in future).
  
  Older LTS branches ship older branches of Flatpak (1.14.x or older) and
  already had several known unfixed vulnerabilities. The Flatpak upstream
  developers are not going to backport security fixes to these old
  branches. If Ubuntu policy is to stick to these older branches, then
  Ubuntu developers will have to be responsible for their security status
  - either backporting a newer upstream release, or backporting individual
  security fixes, or flagging these older versions as end-of-life and
  warning Ubuntu users not to use them.
  
  Flatpak is security-sensitive software and I think it's important to be
  realistic about the extent to which older branches can be supported,
  especially with LLMs hammering all of the world's software looking for
  security vulnerabilities that they can exploit.
  
  The Debian LTS team appears to be considering backporting newer Flatpak
  versions like 1.16.6 into older Debian LTS releases instead of
- attempting to  <https://salsa.debian.org/lts-team/lts-updates-
- tasks/-/work_items/436>. It might be wise for Ubuntu to do similarly.
+ attempting to backport individual security fixes:
+ <https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/436>.
+ It might be wise for Ubuntu to do similarly.
  
  An unofficial backport of modern versions of Flatpak is available in a
  PPA: <https://launchpad.net/~flatpak/+archive/ubuntu/stable>,
  <https://github.com/flatpak/ppa-flatpak>. This does not come with any
  support guarantees, but if nothing else it provides a proof of concept
  illustrating how an Ubuntu developer could provide a more up-to-date
  version of Flatpak.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167694

Title:
  CVE-2026-90616: Flatpak sandbox escape with full host filesystem
  access

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/flatpak/+bug/2167694/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to