-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 11 Aug 2026 14:03:38 +0100
Source: flatpak
Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym
Architecture: arm64
Version: 1.16.6-1~deb13u2
Distribution: trixie-security
Urgency: high
Maintainer: arm64 Build Daemon (arm-ubc-01) <buildd_arm64-arm-ubc-01@buildd.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Description:
 flatpak    - Application deployment framework for desktop apps
 flatpak-tests - Application deployment framework for desktop apps (tests)
 gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection)
 libflatpak-dev - Application deployment framework for desktop apps (development)
 libflatpak0 - Application deployment framework for desktop apps (library)
Closes: 1144130
Changes:
 flatpak (1.16.6-1~deb13u2) trixie-security; urgency=high
 .
   * d/patches: Backport security fixes from 1.18.1 (Closes: #1144130)
     - d/p/libglnx/*.patch:
       Backport glnx_chase_and_mkdirat() utility function, required by some
       of the security fixes below
     - d/p/tests/*.patch:
       Backport unit tests fixes which are required by the tests for some
       of the security fixes below
     - d/p/GHSA-fqx6-vh4p-42cg-GHSA-8qxj-x646-phcm/*.patch:
       + GHSA-fqx6-vh4p-42cg:
         Fix writing outside installation directory via crafted commit metadata.
         A malicious or compromised Flatpak repository could write
         attacker-controlled files outside /var/lib/flatpak as root.
       + GHSA-8qxj-x646-phcm:
         Fix writing outside working directory in `flatpak build-init`.
         A malicious or compromised SDK could write outside the intended
         working directory when a developer starts using it for a build.
     - d/p/GHSA-qrwq-7qwx-q9rp/*.patch:
       Fix local privilege escalation involving revokefs.
       A malicious local user could write files outside /var/lib/flatpak
       as root by tampering with OSTree objects after signature verification.
     - d/p/GHSA-8688-9x26-hhxj/*.patch:
       Fix a sandbox escape involving directories inside ~/.var/app/APP_ID.
       A malicious or compromised Flatpak app could write to arbitrary files
       outside its sandbox.
     - d/p/GHSA-99wv-m8rp-g58x/*.patch:
       Fix a sandbox escape involving the ld.so cache.
       A malicious or compromised Flatpak app could write files with a fixed
       name and limited control over content outside the sandbox.
     - d/p/GHSA-v2gw-v9h5-9q4x/*.patch:
       Fix local privilege escalation involving crafted OCI architecture names.
       A malicious local user on a system with an OCI remote configured
       (unusual on non-Fedora systems) could trick the flatpak-system-helper
       process into writing outside /var/lib/flatpak.
     - d/p/GHSA-w69g-9x8j-7p8f/*.patch:
       Fix reading outside sandbox involving crafted extension metadata.
       A malicious or compromised Flatpak app could find out whether specific
       files exist outside the sandbox.
     - d/p/GHSA-q4gr-vc25-57m5/*.patch:
       Fix anti-downgrade checks for components installed system-wide.
       A malicious local user with an active local login session could
       downgrade an app, runtime or extension to an older, known-vulnerable
       version and use this to attack other local users.
     - d/p/GHSA-jr92-2v97-wgvc/*.patch:
       Fix a buffer overflow when installing or updating from a malicious OCI
       registry, not believed to be practically exploitable on 64-bit systems.
     - d/p/hardening/*.patch:
       Harden file accesses against path traversal, fixing issues that
       were initially thought to be security vulnerabilities similar to
       those above, but on further analysis do not seem to be exploitable.
     - d/p/GHSA-r7hp-698j-2h6c/*.patch:
       Correct xdg-dbus-proxy rules for receiving selected AT-SPI broadcasts
       so that GTK accessibility features work as intended.
       Previously, these accessibility features only worked accidentally as a
       result of an xdg-dbus-proxy security issue, fixed in 0.1.8.
   * d/patches: Add additional bug fixes from upstream 1.16.x branch
     - d/p/subprojects-Ignore-.wraplock-file-generated-by-recent-Mes.patch,
       d/p/bwrap-Clarify-a-comment.patch,
       d/p/subprojects-Update-dbus-proxy.wrap-to-v0.1.7.patch:
       Resync with upstream source, no functional changes
     - d/p/dir-Use-flatpak_bwrap_child_setup_inherit_fds_cb-to-apply.patch:
       Silence a spurious warning when apps use the extra_data mechanism
     - d/p/portal-Actually-use-the-AppInfo-hash-table.patch:
       Fix a memory leak and potential rare crashes in flatpak-portal
Checksums-Sha1:
 47cd3eb92589725434e294da03360345cda8d56e 7634104 flatpak-dbgsym_1.16.6-1~deb13u2_arm64.deb
 edc6f79268b0bebf27cff78c6aa889c582807a78 10936164 flatpak-tests-dbgsym_1.16.6-1~deb13u2_arm64.deb
 3f0eed6efe581d9117326ecf97919a76ebef92a2 1317956 flatpak-tests_1.16.6-1~deb13u2_arm64.deb
 f33e224466449ba7fd22ecd98f16150267205177 17621 flatpak_1.16.6-1~deb13u2_arm64-buildd.buildinfo
 1380962e2fadfc5b50d70e1d15a3d81c43d157e3 1471828 flatpak_1.16.6-1~deb13u2_arm64.deb
 891b61a5dc7669d99759eae7c4d9384c3c1d71e8 29336 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_arm64.deb
 32e65105e731c90650efe19e2e3abe5d40ab93a7 73648 libflatpak-dev_1.16.6-1~deb13u2_arm64.deb
 729bf2962572b179b5efc4ce63371b988773ab8d 1747012 libflatpak0-dbgsym_1.16.6-1~deb13u2_arm64.deb
 2f27fb30055f371ffd3e4872429f718a15195fae 351576 libflatpak0_1.16.6-1~deb13u2_arm64.deb
Checksums-Sha256:
 6b02236aa793c82485c0ce8f2c5ae3c9afbee7faa89735bd1a46c60eb41b2412 7634104 flatpak-dbgsym_1.16.6-1~deb13u2_arm64.deb
 f5ac6761223a7e546ab853589c780317c78441113c5805eb1955b00d864ae64f 10936164 flatpak-tests-dbgsym_1.16.6-1~deb13u2_arm64.deb
 55cd85bc8b9bd9673b0293b02c0abe9425a6cec2ed2dceb14b7de35035edf158 1317956 flatpak-tests_1.16.6-1~deb13u2_arm64.deb
 4aa824732df7e4ea8567475d02dafb068e237a563857645350c490c07068d0a6 17621 flatpak_1.16.6-1~deb13u2_arm64-buildd.buildinfo
 1c7bac26a81712ea9a422a65fb1d1068820c06d2040cb4d85e6e162ea0220a7f 1471828 flatpak_1.16.6-1~deb13u2_arm64.deb
 76a1649d9109b088778198e2e4ab452fc6b093c6fb832269d80d5a6e30355ebf 29336 gir1.2-flatpak-1.0_1.16.6-1~deb13u2_arm64.deb
 aac601c97cb746a468d074e7a1fa3fc329123d338f2a92e671cb20ecca425353 73648 libflatpak-dev_1.16.6-1~deb13u2_arm64.deb
 751ca0b67e471cae6c5b7df3a84149f9096523ca6ee2b238d7606001e20f6cf3 1747012 libflatpak0-dbgsym_1.16.6-1~deb13u2_arm64.deb
 e290bb2c5593400e1e53686de08316707e35da5e61b87116bebdb1512c40695c 351576 libflatpak0_1.16.6-1~deb13u2_arm64.deb
Files:
 dec65504ff7a6da454d84e5892edbb2c 7634104 debug optional flatpak-dbgsym_1.16.6-1~deb13u2_arm64.deb
 f3de344476842337d6de8b315b0b2ce6 10936164 debug optional flatpak-tests-dbgsym_1.16.6-1~deb13u2_arm64.deb
 147d7a2d90675fef8551c20404231146 1317956 misc optional flatpak-tests_1.16.6-1~deb13u2_arm64.deb
 8bafbb023891d3996188a10548082e3a 17621 admin optional flatpak_1.16.6-1~deb13u2_arm64-buildd.buildinfo
 d470f397001cf84e402399ba9d38eda9 1471828 admin optional flatpak_1.16.6-1~deb13u2_arm64.deb
 6bc405f8480ba387244c05320e8bdcbc 29336 introspection optional gir1.2-flatpak-1.0_1.16.6-1~deb13u2_arm64.deb
 e0f35e2af3c4c1637984ac252d658453 73648 libdevel optional libflatpak-dev_1.16.6-1~deb13u2_arm64.deb
 079b26d974911c6fc6a4efd193ad403e 1747012 debug optional libflatpak0-dbgsym_1.16.6-1~deb13u2_arm64.deb
 9cadee3381ce04960853145d60bd471b 351576 libs optional libflatpak0_1.16.6-1~deb13u2_arm64.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE0Ha//LlsGOpbQ/H4xqCFmsOWgoYFAmp7Pd0ACgkQxqCFmsOW
goawgg//c4muxb2bGcmE9aIelzNi4IxDkXM1VMgA8ts4MtJaXE/t6cOVHGjCBal6
yYmkKClWRS8fij0lWJE4RFCEZ8jofdD5ynITnbo+wRMVPaW5gmX8WZIQR1wSZ24N
L38ogkDpT5pYpb+i4HbrJPkkZvMuc3q4DM+6RHeN5KR422xT15Y9UKPCRfRtHndr
V9Eris3QyvcKIFDjeYD7Sa0X6CiGAStiOnub9+OsYDA5wEU6cL/Wk0lywFVMtcPh
dxhKAnoJsC5R689r7apYy6neEvrWWOCB19IT/YYS1MdIUdsuqaUXhOClLe40NCLF
ED/Lvxdcfkj+Ye/42ptv207P7MZy723oeaJH/+srRJxrzEhkUoQ8cCBG16kdnc8I
KSgFHoVBWymtOT34rrwjCx4HOA9l0WaiX1iQLNP/AmDh/tx8tagtlsQoPDJVFpcS
95j3w8MEVZrgYJrI4wZY9HALquFnIQv43P+Ermy4JT/YrcyuVVgTAiw11BThY3rv
v2WMAGd/TTKCY+TjR0u3t3F5i8lcnW9wXgJoaoHP2Zw27+W+7KGZCOJfeUIrvlYm
Ztbp3ZV/QbMGNN8aIofSioELk97pxsVXJhTRfDWWKMku2xvsV3a/HWZCDjlzHf2I
ELcawHk0FOFKU9THrVWtcm2bEm8J+IKeIJAEeUMrJZP7+WNlnkw=
=UTub
-----END PGP SIGNATURE-----
