Debian Package Tracker
Register | Log in
Subscribe

flatpak

Application deployment framework for desktop apps

Choose email to subscribe with

general
  • source: flatpak (main)
  • version: 1.18.4-1
  • maintainer: Utopia Maintenance Team (archive) (DMD)
  • uploaders: Simon McVittie [DMD] – Matthias Klumpp [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.10.8-0+deb11u2
  • o-o-sec: 1.10.8-0+deb11u3
  • oldstable: 1.14.10-1~deb12u2
  • old-sec: 1.14.10-1~deb12u2
  • old-bpo: 1.16.6-1~deb13u1~bpo12+1
  • stable: 1.16.6-1~deb13u1
  • stable-sec: 1.16.6-1~deb13u3
  • testing: 1.18.4-1
  • unstable: 1.18.4-1
versioned links
  • 1.10.8-0+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.10.8-0+deb11u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.14.10-1~deb12u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.16.6-1~deb13u1~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.16.6-1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.16.6-1~deb13u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.18.4-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • flatpak (26 bugs: 0, 24, 2, 0)
  • flatpak-tests
  • gir1.2-flatpak-1.0
  • libflatpak-dev
  • libflatpak-doc
  • libflatpak0
action needed
15 security issues in bookworm high

There are 15 open security issues in bookworm.

15 important issues:
  • CVE-2026-90616: In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app data directories (e.g., /var/cache, /var/data, /var/config, and /var/tmp) in every sandbox on every app launch where, in some cases, components of the path are attacker-controlled. Missing symlink protection can redirect the directories. Some of these directories are bind-mounted by Flatpak by passing the path (e.g., /home/user/.var/app/APP_ID/cache/tmp), which contains attacker-controlled directories (tmp) to bwrap --bind SRC DST. bwrap passes the path on to the kernel, which then follows symlinks. A malicious symlink can point to arbitrary locations on the host and it will become mounted inside the sandbox.
  • CVE-2026-92162:
  • CVE-2026-96275: A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.
  • CVE-2026-96276: If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal.
  • CVE-2026-96280: The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems.
  • CVE-2026-96281: On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.
  • CVE-2026-96282: A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the extension. Additionally, unvalidated extension metadata can cause extension content to be mounted at unintended locations inside the sandbox.
  • CVE-2026-96807: In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. The filenames and content are not attacker controlled, making this hard to exploit.
  • CVE-2026-96808: In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged callers, validated file paths by rejecting literal .. components but did not prevent symlink traversal. A malicious local user in an active local session could obtain two revokefs sessions via the system helper, create a symlink in one session pointing into the other session's directory, and retain a file descriptor through that symlink. This allowed the attacker to modify files belonging to a different revokefs session after they had been validated and imported by the system helper. In particular, an attacker could use this to tamper with ostree commit objects in the system repository after they passed signature verification, enabling root-controlled file writes to attacker-chosen paths and local root privilege escalation.
  • CVE-2026-97023: A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations, the deletion is performed as root.
  • CVE-2026-97024: A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, the write is performed as root.
  • CVE-2026-97025: Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated user against the OCI repository. Only OCI-based sources (e.g. as used by Fedora) are affected; libostree-based sources such as Flathub are not.
  • CVE-2026-97026: Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runtimes, potentially causing installation failures (denial of service); tampered content would fail signature/digest verification rather than being trusted.
  • CVE-2026-97027: Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, instead of validating against an allowlist. A malicious Flatpak app can use this to cause denial of service (e.g. forced application restart loops) or to influence host D-Bus/systemd activation behavior beyond what the sandbox is intended to permit.
  • CVE-2026-97029: Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised Flatpak app can use this to cause denial of service by terminating processes outside its sandbox, such as the desktop shell.
Created: 2026-08-11 Last update: 2026-09-30 18:00
13 security issues in bullseye high

There are 13 open security issues in bullseye.

13 important issues:
  • CVE-2026-34078: Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access to all host files and can be used as a primitive to gain code execution in the host context. This vulnerability is fixed in 1.16.4.
  • CVE-2026-34079: Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the host. This vulnerability is fixed in 1.16.4.
  • TEMP-1132945-4CEFB2:
  • TEMP-1132946-5EDD2C:
  • TEMP-1144130-0EF88B:
  • TEMP-1144130-40A79A:
  • TEMP-1144130-44EC0B:
  • TEMP-1144130-71598F:
  • TEMP-1144130-80BBC5:
  • TEMP-1144130-973A49:
  • TEMP-1144130-B3D5FC:
  • TEMP-1144130-E5141C:
  • TEMP-1144130-FF3646:
Created: 2026-04-08 Last update: 2026-08-29 01:32
Depends on packages which need a new maintainer normal
The packages that flatpak depends on which need a new maintainer are:
  • docbook-xsl (#802370)
    • Build-Depends: docbook-xsl
Created: 2023-09-01 Last update: 2026-10-01 06:31
1 bug tagged help in the BTS normal
The BTS contains 1 bug tagged help, please consider helping the maintainer in dealing with it.
Created: 2025-06-13 Last update: 2026-10-01 06:30
lintian reports 3 warnings normal
Lintian reports 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-09-23 Last update: 2026-09-23 05:30
news
[rss feed]
  • [2026-10-01] flatpak 1.18.4-1 MIGRATED to testing (Debian testing watch)
  • [2026-09-28] Accepted flatpak 1.16.6-1~deb13u3 (source) into stable-security (Debian FTP Masters) (signed by: Simon McVittie)
  • [2026-09-28] Accepted flatpak 1.18.4-1 (source) into unstable (Simon McVittie)
  • [2026-09-27] flatpak 1.18.3-1 MIGRATED to testing (Debian testing watch)
  • [2026-09-22] Accepted flatpak 1.18.3-1 (source) into unstable (Simon McVittie)
  • [2026-09-03] flatpak 1.18.2-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-28] Accepted flatpak 1.18.2-1 (source) into unstable (Simon McVittie)
  • [2026-08-21] Accepted flatpak 1.16.6-1~deb13u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Simon McVittie)
  • [2026-08-17] flatpak 1.18.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-12] Accepted flatpak 1.16.6-1~deb13u2 (source) into stable-security (Debian FTP Masters) (signed by: Simon McVittie)
  • [2026-08-11] Accepted flatpak 1.18.1-1 (source) into unstable (Simon McVittie)
  • [2026-06-24] flatpak 1.18.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-08] Accepted flatpak 1.18.0-1 (source) into unstable (Simon McVittie)
  • [2026-04-25] Accepted flatpak 1.14.10-1~deb12u2 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Simon McVittie)
  • [2026-04-22] Accepted flatpak 1.14.10-1~deb12u2 (source) into oldstable-security (Debian FTP Masters) (signed by: Simon McVittie)
  • [2026-04-18] Accepted flatpak 1.16.6-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Simon McVittie)
  • [2026-04-13] Accepted flatpak 1.17.6-1 (source) into experimental (Simon McVittie)
  • [2026-04-13] Accepted flatpak 1.16.6-1~deb13u1~bpo12+1 (source) into oldstable-backports (Simon McVittie)
  • [2026-04-13] flatpak 1.16.6-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-12] Accepted flatpak 1.16.6-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Simon McVittie)
  • [2026-04-10] Accepted flatpak 1.16.6-1 (source) into unstable (Simon McVittie)
  • [2026-04-10] Accepted flatpak 1.16.5-1 (source) into unstable (Simon McVittie)
  • [2026-04-08] Accepted flatpak 1.16.4-2 (source) into unstable (Simon McVittie)
  • [2026-04-07] Accepted flatpak 1.17.3-2 (source) into experimental (Simon McVittie)
  • [2026-04-07] Accepted flatpak 1.16.4-1 (source) into unstable (Simon McVittie)
  • [2026-03-19] Accepted flatpak 1.17.3-1 (source) into experimental (Simon McVittie)
  • [2026-02-27] Accepted flatpak 1.16.3-1~deb13u1 (source) into proposed-updates (Debian FTP Masters)
  • [2026-01-30] flatpak 1.16.3-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-24] Accepted flatpak 1.16.3-1 (source) into unstable (Simon McVittie)
  • [2026-01-01] Accepted flatpak 1.16.2-1~deb13u1 (source) into proposed-updates (Debian FTP Masters)
  • 1
  • 2
bugs [bug history graph]
  • all: 32
  • RC: 0
  • I&N: 30
  • M&W: 2
  • F&P: 0
  • patch: 0
  • help: 1
links
  • homepage
  • lintian (0, 3)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • l10n (-, 79)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.18.2-1
  • 36 bugs (1 patch)

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing