Your message dated Fri, 21 Aug 2026 13:47:29 +0000
with message-id <[email protected]>
and subject line Bug#1144130: fixed in flatpak 1.16.6-1~deb13u2
has caused the Debian Bug report #1144130,
regarding flatpak: multiple vulnerabilities fixed by 1.18.1
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1144130: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144130
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: flatpak
Severity: critical
Tags: security
X-Debbugs-Cc: Debian Security Team <[email protected]>

This bug report is a placeholder for all of the vulnerabilities that are 
fixed in prerelease 1.19.0. The same vulnerabilities will also be fixed 
in a 1.18.1 stable release, soon. More details when they are available.

    smcv

--- End Message ---
--- Begin Message ---
Source: flatpak
Source-Version: 1.16.6-1~deb13u2
Done: Simon McVittie <[email protected]>

We believe that the bug you reported is fixed in the latest version of
flatpak, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie <[email protected]> (supplier of updated flatpak package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 11 Aug 2026 14:03:38 +0100
Source: flatpak
Architecture: source
Version: 1.16.6-1~deb13u2
Distribution: trixie-security
Urgency: high
Maintainer: Utopia Maintenance Team 
<[email protected]>
Changed-By: Simon McVittie <[email protected]>
Closes: 1144130
Changes:
 flatpak (1.16.6-1~deb13u2) trixie-security; urgency=high
 .
   * d/patches: Backport security fixes from 1.18.1 (Closes: #1144130)
     - d/p/libglnx/*.patch:
       Backport glnx_chase_and_mkdirat() utility function, required by some
       of the security fixes below
     - d/p/tests/*.patch:
       Backport unit tests fixes which are required by the tests for some
       of the security fixes below
     - d/p/GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/*.patch:
       + GHSA-fqx6-vh4p-42cg:
         Fix writing outside installation directory via crafted commit metadata.
         A malicious or compromised Flatpak repository could write
         attacker-controlled files outside /var/lib/flatpak as root.
       + GHSA-8qxj-x646-phcm:
         Fix writing outside working directory in `flatpak build-init`.
         A malicious or compromised SDK could write outside the intended
         working directory when a developer starts using it for a build.
     - d/p/GHSA-qrwq-7qwx-q9rp/*.patch:
       Fix local privilege escalation involving revokefs.
       A malicious local user could write files outside /var/lib/flatpak
       as root by tampering with OSTree objects after signature verification.
     - d/p/GHSA-8688-9x26-hhxj/*.patch:
       Fix a sandbox escape involving directories inside ~/.var/app/APP_ID.
       A malicious or compromised Flatpak app could write to arbitrary files
       outside its sandbox.
     - d/p/GHSA-99wv-m8rp-g58x/*.patch:
       Fix a sandbox escape involving the ld.so cache.
       A malicious or compromised Flatpak app could write files with a fixed
       name and limited control over content outside the sandbox.
     - d/p/GHSA-v2gw-v9h5-9q4x/*.patch:
       Fix local privilege escalation involving crafted OCI architecture names.
       A malicious local user on a system with an OCI remote configured
       (unusual on non-Fedora systems) could trick the flatpak-system-helper
       process into writing outside /var/lib/flatpak.
     - d/p/GHSA-w69g-9x8j-7p8f/*.patch:
       Fix reading outside sandbox involving crafted extension metadata.
       A malicious or compromised Flatpak app could find out whether specific
       files exist outside the sandbox.
     - d/p/GHSA-q4gr-vc25-57m5/*.patch:
       Fix anti-downgrade checks for components installed system-wide.
       A malicious local user with an active local login session could
       downgrade an app, runtime or extension to an older, known-vulnerable
       version and use this to attack other local users.
     - d/p/GHSA-jr92-2v97-wgvc/*.patch:
       Fix a buffer overflow when installing or updating from a malicious OCI
       registry, not believed to be practically exploitable on 64-bit systems.
     - d/p/hardening/*.patch:
       Harden file accesses against path traversal, fixing issues that
       were initially thought to be security vulnerabilities similar to
       those above, but on further analysis do not seem to be exploitable.
     - d/p/GHSA-r7hp-698j-2h6c/*.patch:
       Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts
       so that GTK accessibility features work as intended.
       Previously, these accessibility features only worked accidentally as a
       result of an xdg-dbus-proxy security issue, fixed in 0.1.8.
   * d/patches: Add additional bug fixes from upstream 1.16.x branch
     - d/p/subprojects-Ignore-.wraplock-file-generated-by-recent-Mes.patch,
       d/p/bwrap-Clarify-a-comment.patch,
       d/p/subprojects-Update-dbus-proxy.wrap-to-v0.1.7.patch:
       Resync with upstream source, no functional changes
     - d/p/dir-Use-flatpak_bwrap_child_setup_inherit_fds_cb-to-apply.patch:
       Silence a spurious warning when apps use the extra_data mechanism
     - d/p/portal-Actually-use-the-AppInfo-hash-table.patch:
       Fix a memory leak and potential rare crashes in flatpak-portal
Checksums-Sha1:
 23819bb80df3336957c6a48b2d9e8b8cb2d47237 3741 flatpak_1.16.6-1~deb13u2.dsc
 ba597a6fe31a0749cb3f8835b72885e5b235b9d2 76448 
flatpak_1.16.6-1~deb13u2.debian.tar.xz
 131e098bbf4d64f1f69a4ceb55f12949f12b4b87 15293 
flatpak_1.16.6-1~deb13u2_source.buildinfo
Checksums-Sha256:
 5aa8c6319336226ac6638acd8df94b63bc27da4621a478f3e47e0f9f564c18de 3741 
flatpak_1.16.6-1~deb13u2.dsc
 bac37dc8430afe688734263f7efecb8a9bfff6098011d24a1647b2f09c99d790 76448 
flatpak_1.16.6-1~deb13u2.debian.tar.xz
 cd3a79eddc583a2c65b61a71f05b936bef12a05362d5caa2233b3e1ed7bf00f6 15293 
flatpak_1.16.6-1~deb13u2_source.buildinfo
Files:
 4ca674bfa72b7210851606ff843ed90e 3741 admin optional 
flatpak_1.16.6-1~deb13u2.dsc
 51eeccf1f9d601f93a4a2ca595a714fe 76448 admin optional 
flatpak_1.16.6-1~deb13u2.debian.tar.xz
 c295c3e06eaf5d5e5a86cfe665b6a27c 15293 admin optional 
flatpak_1.16.6-1~deb13u2_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmp7OMQACgkQI1wJnT6z
MHbM7BAAyWAr40Kt7lpDvCJmkCS1LcRTBexSBmchq8rrP0yeLQwoJ3KynC0lI7FO
ZhwhmnqCeBu+s0X5dH409FYGV8SimHLWw7ihPnnqZUvc0bjEGidanULENxnb3r2G
v5r6RrI93xUZDVkR3ZyrHBUV4i4WSZJD9dMKf91UWuFh2InPz2edIhi86nRkZSox
r4VDn6/AArAJ5yfBOeV001AUOGwFVvCmzZzYmys1Bl0aTtHDeJrZu7aE3JIsf1li
AeHxN7sul1Ti3hqtlglL7ISVsdNycgqqU8T4osTDDfOU5Xk2yGk97yePRuZ1Du4I
p5h+3IWAQMoOsZy3eYnKALiObqtGmW8iZw4SYLdNOtPLmmlynvbcfffoEe6r9JCz
3ONRXTmu6KpwQFXVPx0oAN9z0sz8ynA8SeXxg4Q0YfsVA/+cT6PdAfzNezvFbEM8
yYn4MOgi3iI5XPx9UG2ecitUZAPjRbG3py7ey9k3qVuP7XcvI28umZ0opPPjHCZ9
AHZmIQHz9WYHsJSGxI8cvXgNYDp4SCSk3KWfj0Go+q/wvRW00FYW+2AiKELuNauN
vY/cgKw4/xorvUYTzBRoy3e2YD0QHbAYgW6Z9UbxKgyp1gpeW9nxim8nNYFlPooK
EVVffgpmXh8hX/FvX57s5/tZ7qzeVHN/uu4hqv4QdorQgW/rVRs=
=d3BX
-----END PGP SIGNATURE-----

Attachment: pgpEwYwQ2N4BQ.pgp
Description: PGP signature


--- End Message ---
_______________________________________________
Pkg-utopia-maintainers mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-utopia-maintainers

Reply via email to