[ubuntu/resolute-proposed] flatpak 1.16.4-1 (Accepted)

Sebastien Bacher sebastien.bacher at canonical.com
Wed Apr 8 09:03:15 UTC 2026


flatpak (1.16.4-1) unstable; urgency=high

  * New upstream security release
    - Fix a sandbox escape involving symlinks passed to flatpak-portal.
      A malicious or compromised Flatpak app could exploit this to achieve
      arbitrary code execution on the host.
      (CVE-2026-34078, GHSA-cc2q-qc34-jprg)
    - Prevent arbitrary file deletion outside the sandbox by a malicious or
      compromised Flatpak app
      (CVE-2026-34079, GHSA-p29x-r292-46pp)
    - Prevent a local user from reading any file that is readable by the
      _flatpak system user. A mitigation is that it would be very unusual
      for these files not to be readable by the original local user as well.
      (No CVE ID, GHSA-2fxp-43j9-pwvc)
    - Prevent a local user from making another local user unable to cancel
      an ongoing download of apps or runtimes installed system-wide
      via the system helper.
      (No CVE ID, GHSA-89xm-3m96-w3jg)

Date: 2026-04-08 04:45:52.158547+00:00
Signed-By: Sebastien Bacher <sebastien.bacher at canonical.com>
https://launchpad.net/ubuntu/+source/flatpak/1.16.4-1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list