Skip to content

[Deepin Integration]~[v25-Release] feat: update flatpak to 1.16.6-1~deb13u1 by deepin-community-bot[bot]@deepin-community/flatpak by deepin-community-ci-bot[bot] #13772

Description

@deepin-bot

Package information | 软件包信息

包名 版本
flatpak 1.16.6-1~deb13u1

Package repository address | 软件包仓库地址

deb [trusted=yes] https://ci.deepin.com/repo/obs/deepin:/CI:/TestingIntegration:/test-integration-pr-4427/testing/ ./

Changelog | 更新信息

flatpak (1.16.6-1~deb13u1) trixie-security; urgency=high

  • Backport new upstream stable release for Debian 13
    • Fix a sandbox escape involving symlinks passed to flatpak-portal.
      A malicious or compromised Flatpak app could exploit this to achieve
      arbitrary code execution on the host.
      (CVE-2026-34078, GHSA-cc2q-qc34-jprg) (Closes: #1132943)
    • Prevent arbitrary file deletion outside the sandbox by a malicious or
      compromised Flatpak app
      (CVE-2026-34079, GHSA-p29x-r292-46pp) (Closes: #1132944)
    • Prevent a local user from reading any file that is readable by the
      _flatpak system user. A mitigation is that it would be very unusual
      for these files not to be readable by the original local user as well.
      (No CVE ID, GHSA-2fxp-43j9-pwvc) (Closes: #1132946)
    • Prevent a local user from making another local user unable to cancel
      an ongoing download of apps or runtimes installed system-wide
      via the system helper.
      (No CVE ID, GHSA-89xm-3m96-w3jg) (Closes: #1132945)
    • Various fixes for regressions caused when fixing CVE-2026-34078
  • Revert changes that are not appropriate for a stable update:
    • Revert "d/watch: Convert to v5 format, only watch stable
      (even-numbered) releases"
    • Revert "Standards-Version: 4.7.3"

Metadata

Metadata

Labels

Type

No type

Projects

Status
In progress

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions