*** This bug is a security vulnerability *** Public security bug reported:
Upstream advisory: https://github.com/flatpak/flatpak/security/advisories/GHSA-8qxj-x646-phcm This is one of several vulnerabilities fixed in 1.18.1 upstream: https://www.openwall.com/lists/oss-security/2026/08/11/9 The 1.16.x branch is no longer supported upstream and will not receive new releases, but backports of the 1.18.1 security fixes are available in the flatpak-1.16.x branch upstream, and in Debian 13. See also https://bugs.launchpad.net/ubuntu/+source/flatpak/+bug/2167694, everything I said there applies equally here. ** Affects: flatpak (Ubuntu) Importance: Undecided Status: New ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2167701 Title: GHSA-8qxj-x646-phcm: Arbitrary write in host context via `flatpak build-init` To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/flatpak/+bug/2167701/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
