*** This bug is a security vulnerability *** Public security bug reported:
Upstream advisory: https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj This is one of several vulnerabilities fixed in 1.18.1 upstream: https://www.openwall.com/lists/oss-security/2026/08/11/9 The 1.16.x branch is no longer supported upstream and will not receive new releases, but backports of the 1.18.1 security fixes are available in the flatpak-1.16.x branch upstream, and in Debian 13. Ubuntu 26.04 LTS 'resolute' currently ships Flatpak 1.16.6. If backporting 1.18.x is not acceptable, then I would recommend updating the package to be equivalent to what's in Debian 13 security update https://lists.debian.org/debian-security-announce/2026/msg00343.html (and then keeping it in sync with what's in Debian 13 security updates in future). Older LTS branches ship older branches of Flatpak (1.14.x or older) and already had several known unfixed vulnerabilities. The Flatpak upstream developers are not going to backport security fixes to these old branches. If Ubuntu policy is to stick to these older branches, then Ubuntu developers will have to be responsible for their security status - either backporting a newer upstream release, or backporting individual security fixes, or flagging these older versions as end-of-life and warning Ubuntu users not to use them. Flatpak is security-sensitive software and I think it's important to be realistic about the extent to which older branches can be supported, especially with LLMs hammering all of the world's software looking for security vulnerabilities that they can exploit. The Debian LTS team appears to be considering backporting newer Flatpak versions like 1.16.6 into older Debian LTS releases instead of attempting to backport individual security fixes: <https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/436>. It might be wise for Ubuntu to do similarly. An unofficial backport of modern versions of Flatpak is available in a PPA: <https://launchpad.net/~flatpak/+archive/ubuntu/stable>, <https://github.com/flatpak/ppa-flatpak>. This does not come with any support guarantees, but if nothing else it provides a proof of concept illustrating how an Ubuntu developer could provide a more up-to-date version of Flatpak. ** Affects: flatpak (Ubuntu) Importance: Undecided Status: New ** Information type changed from Private Security to Public Security ** CVE added: https://cve.org/CVERecord?id=CVE-2026-90616 ** Description changed: Upstream advisory: https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj This is one of several vulnerabilities fixed in 1.18.1 upstream: https://www.openwall.com/lists/oss-security/2026/08/11/9 The 1.16.x branch is no longer supported upstream and will not receive new releases, but backports of the 1.18.1 security fixes are available in the flatpak-1.16.x branch upstream, and in Debian 13. Ubuntu 26.04 LTS 'resolute' currently ships Flatpak 1.16.6. If backporting 1.18.x is not acceptable, then I would recommend updating the package to be equivalent to what's in Debian 13 security update https://lists.debian.org/debian-security-announce/2026/msg00343.html (and then keeping it in sync with what's in Debian 13 security updates in future). Older LTS branches ship older branches of Flatpak (1.14.x or older) and already had several known unfixed vulnerabilities. The Flatpak upstream developers are not going to backport security fixes to these old branches. If Ubuntu policy is to stick to these older branches, then Ubuntu developers will have to be responsible for their security status - either backporting a newer upstream release, or backporting individual security fixes, or flagging these older versions as end-of-life and warning Ubuntu users not to use them. Flatpak is security-sensitive software and I think it's important to be realistic about the extent to which older branches can be supported, especially with LLMs hammering all of the world's software looking for security vulnerabilities that they can exploit. The Debian LTS team appears to be considering backporting newer Flatpak versions like 1.16.6 into older Debian LTS releases instead of - attempting to <https://salsa.debian.org/lts-team/lts-updates- - tasks/-/work_items/436>. It might be wise for Ubuntu to do similarly. + attempting to backport individual security fixes: + <https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/436>. + It might be wise for Ubuntu to do similarly. An unofficial backport of modern versions of Flatpak is available in a PPA: <https://launchpad.net/~flatpak/+archive/ubuntu/stable>, <https://github.com/flatpak/ppa-flatpak>. This does not come with any support guarantees, but if nothing else it provides a proof of concept illustrating how an Ubuntu developer could provide a more up-to-date version of Flatpak. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2167694 Title: CVE-2026-90616: Flatpak sandbox escape with full host filesystem access To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/flatpak/+bug/2167694/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
