[ubuntu/resolute-proposed] flatpak 1.16.4-1 (Accepted)
Sebastien Bacher
sebastien.bacher at canonical.com
Wed Apr 8 09:03:15 UTC 2026
flatpak (1.16.4-1) unstable; urgency=high
* New upstream security release
- Fix a sandbox escape involving symlinks passed to flatpak-portal.
A malicious or compromised Flatpak app could exploit this to achieve
arbitrary code execution on the host.
(CVE-2026-34078, GHSA-cc2q-qc34-jprg)
- Prevent arbitrary file deletion outside the sandbox by a malicious or
compromised Flatpak app
(CVE-2026-34079, GHSA-p29x-r292-46pp)
- Prevent a local user from reading any file that is readable by the
_flatpak system user. A mitigation is that it would be very unusual
for these files not to be readable by the original local user as well.
(No CVE ID, GHSA-2fxp-43j9-pwvc)
- Prevent a local user from making another local user unable to cancel
an ongoing download of apps or runtimes installed system-wide
via the system helper.
(No CVE ID, GHSA-89xm-3m96-w3jg)
Date: 2026-04-08 04:45:52.158547+00:00
Signed-By: Sebastien Bacher <sebastien.bacher at canonical.com>
https://launchpad.net/ubuntu/+source/flatpak/1.16.4-1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list