Hi Simon, On Tue, Aug 11, 2026 at 02:50:41PM +0100, Simon McVittie wrote: > On Tue, 11 Aug 2026 at 13:32:05 +0100, Simon McVittie wrote: > > This bug report is a placeholder for all of the vulnerabilities that are > > fixed in prerelease 1.19.0. The same vulnerabilities will also be fixed > > in a 1.18.1 stable release, soon. More details when they are available. > > https://github.com/flatpak/flatpak/releases/tag/1.18.1 lists all the > vulnerabilities. We don't have CVE IDs for any of them yet, so they're > referenced by GHSA- IDs. > > The most serious are a full sandbox escape (GHSA-8688-9x26-hhxj) and local > root privilege escalation (GHSA-qrwq-7qwx-q9rp, GHSA-fqx6-vh4p-42cg). > > I will upload 1.18.1 to unstable soon: automated tests are still running, > but manual testing was successful. > > All of the vulnerabilities except for GHSA-9rww-v4mm-x4jg affect trixie as > well. GHSA-9rww-v4mm-x4jg is a problem with a new feature that was added in > the 1.17.x/1.18.x cycle, so trixie is not vulnerable to it. > > https://people.debian.org/~smcv/bug1144130/trixie/ contains backported fixes > for trixie, covering everything except GHSA-9rww-v4mm-x4jg. As discussed by > private email with the security team, this also includes pending upstream > non-security bug fixes from the flatpak-1.16.x branch. May I upload?
Yes please do upload to security-master (just confirming, you should already have an ack from Moritz on the flatpak update). Regards, Salvatore

